Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
RUSTSEC-2026-0299
  • crates.io/owned-alloc
`owned-alloc` is unmaintained just now
  • No fix available
RUSTSEC-2026-0293
  • crates.io/ringbuf
Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics 20 hours ago
  • Fix available
RUSTSEC-2026-0296
  • crates.io/unzip
`unzip` is unmaintained 20 hours ago
  • No fix available
RUSTSEC-2026-0294
  • crates.io/iceoryx2-bb-container
Unsoundness in UTF-8 'String' trait 3 days ago
  • Fix available
GHSA-4rf6-qx84-q9fv
  • crates.io/fulgur
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service) 4 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-j5cx-ph8g-95v3
  • crates.io/fulgur
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service 4 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-9g45-5xwm-f3wc
  • crates.io/rmcp
RMCP: Custom HTTP headers leak to cross-origin redirect targets 4 days ago
  • Fix available
  • Severity - 6.8 (Medium)
RUSTSEC-2026-0287
  • crates.io/cosmian_kyber
cosmian_kyber is unmaintained 4 days ago
  • No fix available
RUSTSEC-2026-0289
  • crates.io/pqc_kyber
pqc_kyber is unmaintained 4 days ago
  • No fix available
GHSA-9pj6-vhgr-3mwh
  • crates.io/rmcp
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service 5 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-33f5-2c5q-wgwj
  • crates.io/rmcp
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery 5 days ago
  • Fix available
  • Severity - 8.2 (High)
RUSTSEC-2026-0286
  • crates.io/cryptoki
Out-of-bounds read when decoding CKA_ALLOWED_MECHANISMS 5 days ago
  • Fix available
GHSA-5hq8-qhww-jm7q
  • crates.io/libp2p-quic
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake 6 days ago
  • Fix available
  • Severity - 8.2 (High)
RUSTSEC-2026-0285
  • crates.io/rustls
TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries 14 Sep
  • Fix available
  • Severity - 5.3 (Medium)
RUSTSEC-2026-0283
  • crates.io/clear_on_drop
clear_on_drop is unmaintained 13 Sep
  • No fix available
RUSTSEC-2026-0298
  • crates.io/unicycle
Use-after-free when a future's `Drop` panics while the container is dropped 12 Sep
  • Fix available