Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
RUSTSEC-2026-0236
  • crates.io/viperjs
A `BigInt` division panics, and two neighbouring operations answer wrongly in silence 2 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-m65r-rprj-r5rg
  • crates.io/russh
Russh: Channel-scoped server callbacks can be reached without an open channel 5 days ago
  • Fix available
  • Severity - 6.5 (Medium)
RUSTSEC-2026-0224
  • crates.io/nostr-relay-pool
Verification cache poisoning allows forged Nostr events to bypass signature validation 01 Aug
  • Fix available
  • Severity - 7.5 (High)
RUSTSEC-2026-0225
  • crates.io/nostr
Debug output exposes NIP-46 and NIP-60 credentials 01 Aug
  • Fix available
  • Severity - 5.5 (Medium)
RUSTSEC-2026-0226
  • crates.io/nostr
Wallet event parsers accept unauthenticated events 01 Aug
  • Fix available
  • Severity - 7.5 (High)
RUSTSEC-2026-0227
  • crates.io/nostr
NIP-44 v2 decryption permits resource exhaustion 01 Aug
  • Fix available
  • Severity - 7.5 (High)
RUSTSEC-2026-0228
  • crates.io/nostr
NIP-04 parsing amplifies malformed ciphertext memory use 01 Aug
  • Fix available
  • Severity - 4.3 (Medium)
RUSTSEC-2026-0229
  • crates.io/nostr
NIP-98 authorization parsing permits resource exhaustion 01 Aug
  • Fix available
  • Severity - 7.5 (High)
RUSTSEC-2026-0230
  • crates.io/nostr
Empty NIP-50 search filters can panic 01 Aug
  • Fix available
  • Severity - 7.5 (High)
RUSTSEC-2026-0231
  • crates.io/nostr-relay-pool
Relay authentication challenges can exhaust memory 01 Aug
  • Fix available
  • Severity - 7.5 (High)
RUSTSEC-2026-0232
  • crates.io/nostr-relay-pool
Processing of unverified relay events 01 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-3whf-vgf2-9w6g
  • crates.io/zaino-state
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit 31 Jul
  • Fix available
  • Severity - 6.9 (Medium)
RUSTSEC-2026-0222
  • crates.io/wasmtime
Stores can mix up type indices between engines 31 Jul
  • Fix available
  • Severity - 3.8 (Low)
RUSTSEC-2026-0223
  • crates.io/wasmtime
Preemption and traps during bulk operations enable breaking internal VM state 31 Jul
  • Fix available
  • Severity - 2.0 (Low)
GHSA-6xx4-9wp6-65p7
  • crates.io/skilo
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source 28 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-hc4m-q9jh-xw4j
  • crates.io/nono-cli
nono-cli'scregistry pack verification can fail open when provenance metadata is absent 28 Jul
  • Fix available
  • Severity - 6.6 (Medium)