Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-2cv4-cqwr-gwf7
  • PyPI/uv
  • crates.io/uv
uv: Path traversal on Windows through wheel extraction 8 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-2mjx-qc3c-rqvc
  • crates.io/rustls
Rustls: TLS 1.3 handshake messages incorrectly accepted across encryption level... 9 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-6f2x-v7q7-m7m5
  • crates.io/hickory-resolver
hickory-resolver follows irrelevant CNAME records 9 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-6w6g-hm98-mhgm
  • crates.io/hickory-resolver
hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send`... 9 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-5j98-2g5x-46v6
  • crates.io/hickory-resolver
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures 9 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-cjcg-cxmh-9wcr
  • crates.io/praxis-proxy
Praxis affected by HTTP/2 Bomb 3 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-2hw9-mc66-jc2q
  • crates.io/wasmtime
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state 3 days ago
  • Fix available
  • Severity - 2.0 (Low)
GHSA-8ffr-xgwf-xj56
  • crates.io/aws-smithy-json
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers 3 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-6g2r-675j-hx59
  • crates.io/xxhash-rust
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release 3 days ago
  • Fix available
  • Severity - 2.3 (Low)
GHSA-c9xm-49cp-xcr9
  • crates.io/rmcp
rmcp OAuth client fetches server-controlled resource_metadata URLs 3 days ago
  • Fix available
  • Severity - 6.3 (Medium)
RUSTSEC-2026-0319
  • crates.io/anymap2
anymap2 is unmaintained 3 days ago
  • No fix available
RUSTSEC-2026-0320
  • crates.io/wasmtime-wasi-http
Wasmtime wasi:http implementation panics with a zero timeout supplied 3 days ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0321
  • crates.io/wasmtime-wasi
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption 3 days ago
  • Fix available
  • Severity - 4.0 (Medium)
RUSTSEC-2026-0322
  • crates.io/wasmtime-wasi
Excessive allocated memory on the host when guests don't have stdio 3 days ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0323
  • crates.io/wasmtime-wasi
fd_readdir copies uninitialized struct padding into guest memory 3 days ago
  • Fix available
  • Severity - 2.1 (Low)
RUSTSEC-2026-0324
  • crates.io/wasmtime-wasi
Guest can panic host through filesystem timestamp before the epoch on wasip3 3 days ago
  • Fix available
  • Severity - 6.2 (Medium)