Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
OSV Rustsec π¦ is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| rustsec-2026-0318 | Sending custom to-device messages may panics | 2026-09-29T12:00:00Z | 2026-10-01T20:25:27Z |
| rustsec-2026-0317 | A 512-byte workbook can provoke a multi-gigabyte allocation and abort the process | 2026-09-29T12:00:00Z | 2026-10-01T07:31:41Z |
| rustsec-2026-0311 | Stack overflow on deeply nested LaTeX input | 2026-09-27T12:00:00Z | 2026-09-28T08:34:35Z |
| rustsec-2026-0310 | Various panics, soundness and resource exhaustion issues | 2026-09-25T12:00:00Z | 2026-09-25T17:51:57Z |
| rustsec-2026-0316 | Dynamic record lifting can allocate beyond the hostcall fuel limit | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0315 | `call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0314 | Guest can panic host through filesystem datetime overflow | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0313 | Outgoing HTTP body write allows guest-driven host memory exhaustion | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0312 | Excluded iPAddress name constraints with an all-zero mask are not applied | 2026-09-24T12:00:00Z | 2026-09-28T09:30:11Z |
| rustsec-2026-0308 | Use-after-free in interned values and cached function results | 2026-09-24T12:00:00Z | 2026-09-24T14:38:19Z |
| rustsec-2026-0307 | `uncbv`: archive extraction is vulnerable to path traversal (zip-slip) | 2026-09-23T12:00:00Z | 2026-09-24T08:52:17Z |
| rustsec-2026-0305 | Use-after-free when XML includes have duplicated entities | 2026-09-23T12:00:00Z | 2026-10-01T19:14:05Z |
| rustsec-2026-0303 | `stack-graphs` is archived and unmaintained | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0302 | `stack-graphs` C API exports are safe `extern "C"` functions | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0301 | Double free in `StackVec::retain` when a predicate or element `Drop` panics | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0299 | `owned-alloc` is unmaintained | 2026-09-22T12:00:00Z | 2026-09-22T07:35:37Z |
| rustsec-2026-0304 | Finished streaming calls keep reading a stalled request body indefinitely | 2026-09-21T12:00:00Z | 2026-09-23T07:36:54Z |
| rustsec-2026-0296 | `unzip` is unmaintained | 2026-09-21T12:00:00Z | 2026-09-21T15:17:02Z |
| rustsec-2026-0293 | Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics | 2026-09-21T12:00:00Z | 2026-09-21T09:10:46Z |
| rustsec-2026-0309 | `SinglyLinkedList::remove` dereferences a null link | 2026-09-20T12:00:00Z | 2026-09-25T17:51:57Z |
| rustsec-2026-0306 | `hex_decode_unchecked` AVX2 path reads past `src` | 2026-09-20T12:00:00Z | 2026-09-23T14:07:49Z |
| rustsec-2026-0294 | Unsoundness in UTF-8 'String' trait | 2026-09-18T12:00:00Z | 2026-09-21T09:29:57Z |
| rustsec-2026-0289 | pqc_kyber is unmaintained | 2026-09-17T12:00:00Z | 2026-09-18T09:06:23Z |
| rustsec-2026-0287 | cosmian_kyber is unmaintained | 2026-09-17T12:00:00Z | 2026-09-18T09:06:23Z |
| rustsec-2026-0286 | Out-of-bounds read when decoding CKA_ALLOWED_MECHANISMS | 2026-09-16T12:00:00Z | 2026-09-17T07:37:14Z |
| rustsec-2026-0285 | TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries | 2026-09-14T12:00:00Z | 2026-09-14T16:06:06Z |
| rustsec-2026-0283 | clear_on_drop is unmaintained | 2026-09-13T12:00:00Z | 2026-09-13T20:05:24Z |
| rustsec-2026-0298 | Use-after-free when a future's `Drop` panics while the container is dropped | 2026-09-12T12:00:00Z | 2026-09-22T07:35:37Z |
| rustsec-2026-0297 | `unzip`: archive extraction is vulnerable to path traversal (zip-slip) | 2026-09-09T12:00:00Z | 2026-09-21T15:17:02Z |
| rustsec-2026-0291 | Double free in `OwnedAlloc::drop_in_place` when the contained value's `Drop` panics | 2026-09-09T12:00:00Z | 2026-09-21T09:00:40Z |