Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-qwgh-2vcv-g2f7
  • crates.io/block_buffer
block_buffer: panic corrupts inline buffer position 2 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-vjf8-9fx6-mv6x
  • crates.io/triton-vm
Triton VM Soundness Vulnerability due to Missing Constraint yesterday
  • Fix available
  • Severity - 6.9 (Medium)
RUSTSEC-2026-0258
  • crates.io/h2
h2 unbounded empty DATA frames 2 days ago
  • Fix available
GHSA-9q54-f358-3fqf
  • crates.io/s2n-quic
s2n-quic has excessive memory allocation 4 days ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-8rw6-p7m8-63jp
  • crates.io/surrealdb
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users 5 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-3763-qp59-59vf
  • crates.io/nimiq-blockchain
nimiq-blockchain: Validity store off by one error 12 Aug
  • Fix available
  • Severity - 7.5 (High)
RUSTSEC-2026-0252
  • crates.io/orx-split-vec
Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read) 11 Aug
  • Fix available
RUSTSEC-2026-0254
  • crates.io/sp-sized-chunks
Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free) 11 Aug
  • No fix available
RUSTSEC-2026-0255
  • crates.io/sized-chunks
Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free) 11 Aug
  • No fix available
RUSTSEC-2026-0256
  • crates.io/circular-buffer
Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free) 11 Aug
  • Fix available
RUSTSEC-2026-0238
  • crates.io/dcrypt-algorithms
Low-level GCM ignores the operation nonce 09 Aug
  • Fix available
RUSTSEC-2026-0239
  • crates.io/dcrypt-symmetric
Streaming AEAD does not authenticate stream structure 09 Aug
  • Fix available
RUSTSEC-2026-0240
  • crates.io/dcrypt-sign
Ed25519 identity public keys permit universal signature forgery 09 Aug
  • Fix available
RUSTSEC-2026-0242
  • crates.io/dcrypt-api
Safe ErrorRegistry APIs can cause undefined behavior 09 Aug
  • Fix available
RUSTSEC-2026-0236
  • crates.io/viperjs
A `BigInt` division panics, and two neighbouring operations answer wrongly in silence 06 Aug
  • Fix available
  • Severity - 7.5 (High)
RUSTSEC-2026-0244
  • crates.io/gettext-rs
`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization 06 Aug
  • Fix available