Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-434x-w66g-qw3r
  • crates.io/bytes
bytes has integer overflow in BytesMut::reserve 16 hours ago
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-h395-gr6q-cpjc
  • crates.io/jsonwebtoken
jsonwebtoken has Type Confusion that leads to potential authorization bypass 17 hours ago
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-r54g-49rx-98cr
  • crates.io/rustfs
RustFS Logs Sensitive Credentials in Plaintext 18 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-fc6g-2gcp-2qrq
  • crates.io/rustfs
RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers 18 hours ago
  • Fix available
  • Severity - 7.7 (High)
RUSTSEC-2026-0007
  • crates.io/bytes
Integer overflow in `BytesMut::reserve` 23 hours ago
  • Fix available
GHSA-h37v-hp6w-2pp8
  • crates.io/ml-dsa
ml-dsa's UseHint function has off by two error when r0 equals zero yesterday
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-96xm-fv9w-pf3f
  • crates.io/soroban-sdk
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64 6 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-5x2r-hc65-25f9
  • crates.io/ml-dsa
ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices 6 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-253q-9q78-63x4
  • crates.io/clatter
Clatter has a PSK Validity Rule Violation issue 6 days ago
  • Fix available
  • Severity - 8.0 (High)
GHSA-x5m4-43jf-hh65
  • crates.io/soroban-fixed-point-math
soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-rvr2-r3pv-5m4p
  • crates.io/oneshot
oneshot has potential Use After Free when used asynchronously 27 Jan
  • Fix available
  • Severity - 8.2 (High)
GHSA-vc8c-j3xm-xj73
  • crates.io/wasmtime
Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64 27 Jan
  • Fix available
  • Severity - 4.1 (Medium)
GHSA-796p-j2gh-9m2q
  • PyPI/dcap-qvl
  • crates.io/dcap-qvl
  • npm/@phala/dcap-qvl
  • npm/@phala/dcap-qvl-node
  • npm/@phala/dcap-qvl-web
dcap-qvl has Missing Verification for QE Identity 26 Jan
  • Fix available
  • Severity - 9.3 (Critical)
RUSTSEC-2026-0006
  • crates.io/wasmtime
Wasmtime segfault or unused out-of-sandbox load with `f64.copysign` operator on x86-64 26 Jan
  • Fix available
  • Severity - 4.1 (Medium)
RUSTSEC-2026-0005
  • crates.io/oneshot
Potential use-after-free in `oneshot` when used asynchronously 25 Jan
  • Fix available
GHSA-mxc8-4jqf-368q
  • crates.io/miniserve
miniserve affected by a TOCTOU and symlink race vulnerability 23 Jan
  • Fix available
  • Severity - 6.3 (Medium)