Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
OSV Rustsec π¦ is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| rustsec-2026-0319 | anymap2 is unmaintained | 2026-10-02T12:00:00Z | 2026-10-02T08:58:33Z |
| rustsec-2026-0318 | Sending custom to-device messages may panics | 2026-09-29T12:00:00Z | 2026-10-01T20:25:27Z |
| rustsec-2026-0305 | Use-after-free when XML includes have duplicated entities | 2026-09-23T12:00:00Z | 2026-10-01T19:14:05Z |
| rustsec-2026-0317 | A 512-byte workbook can provoke a multi-gigabyte allocation and abort the process | 2026-09-29T12:00:00Z | 2026-10-01T07:31:41Z |
| rustsec-2026-0213 | XSS in ammonia via SVG `animate` and `set` animation tags | 2026-07-21T12:00:00Z | 2026-09-30T07:15:39Z |
| rustsec-2026-0316 | Dynamic record lifting can allocate beyond the hostcall fuel limit | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0315 | `call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0314 | Guest can panic host through filesystem datetime overflow | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0313 | Outgoing HTTP body write allows guest-driven host memory exhaustion | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0312 | Excluded iPAddress name constraints with an all-zero mask are not applied | 2026-09-24T12:00:00Z | 2026-09-28T09:30:11Z |
| rustsec-2026-0311 | Stack overflow on deeply nested LaTeX input | 2026-09-27T12:00:00Z | 2026-09-28T08:34:35Z |
| rustsec-2026-0310 | Various panics, soundness and resource exhaustion issues | 2026-09-25T12:00:00Z | 2026-09-25T17:51:57Z |
| rustsec-2026-0309 | `SinglyLinkedList::remove` dereferences a null link | 2026-09-20T12:00:00Z | 2026-09-25T17:51:57Z |
| rustsec-2018-0011 | Enum repr causing potential memory corruption | 2018-12-18T12:00:00Z | 2026-09-25T14:37:42Z |
| rustsec-2026-0279 | Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution | 2026-06-02T12:00:00Z | 2026-09-25T11:52:38Z |
| rustsec-2026-0308 | Use-after-free in interned values and cached function results | 2026-09-24T12:00:00Z | 2026-09-24T14:38:19Z |
| rustsec-2026-0307 | `uncbv`: archive extraction is vulnerable to path traversal (zip-slip) | 2026-09-23T12:00:00Z | 2026-09-24T08:52:17Z |
| rustsec-2026-0306 | `hex_decode_unchecked` AVX2 path reads past `src` | 2026-09-20T12:00:00Z | 2026-09-23T14:07:49Z |
| rustsec-2026-0304 | Finished streaming calls keep reading a stalled request body indefinitely | 2026-09-21T12:00:00Z | 2026-09-23T07:36:54Z |
| rustsec-2026-0303 | `stack-graphs` is archived and unmaintained | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0302 | `stack-graphs` C API exports are safe `extern "C"` functions | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0301 | Double free in `StackVec::retain` when a predicate or element `Drop` panics | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0175 | `onering` 1.4.1 was removed from crates.io for malicious code | 2026-06-10T12:00:00Z | 2026-09-22T15:16:11Z |
| rustsec-2026-0300 | Use-after-free in `clear` and `retain` when an element's `Drop` panics | 2026-09-02T12:00:00Z | 2026-09-22T07:35:37Z |
| rustsec-2026-0299 | `owned-alloc` is unmaintained | 2026-09-22T12:00:00Z | 2026-09-22T07:35:37Z |
| rustsec-2026-0298 | Use-after-free when a future's `Drop` panics while the container is dropped | 2026-09-12T12:00:00Z | 2026-09-22T07:35:37Z |
| rustsec-2026-0297 | `unzip`: archive extraction is vulnerable to path traversal (zip-slip) | 2026-09-09T12:00:00Z | 2026-09-21T15:17:02Z |
| rustsec-2026-0296 | `unzip` is unmaintained | 2026-09-21T12:00:00Z | 2026-09-21T15:17:02Z |
| rustsec-2026-0295 | Memory corruption bug on `ApplyResult` type | 2026-08-12T12:00:00Z | 2026-09-21T10:08:00Z |
| rustsec-2026-0294 | Unsoundness in UTF-8 'String' trait | 2026-09-18T12:00:00Z | 2026-09-21T09:29:57Z |