Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-cjcg-cxmh-9wcr
  • crates.io/praxis-proxy
Praxis affected by HTTP/2 Bomb 1 hour ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-2hw9-mc66-jc2q
  • crates.io/wasmtime
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state 2 hours ago
  • Fix available
  • Severity - 2.0 (Low)
GHSA-8ffr-xgwf-xj56
  • crates.io/aws-smithy-json
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers 2 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-6g2r-675j-hx59
  • crates.io/xxhash-rust
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release 6 hours ago
  • Fix available
  • Severity - 2.3 (Low)
GHSA-c9xm-49cp-xcr9
  • crates.io/rmcp
rmcp OAuth client fetches server-controlled resource_metadata URLs 8 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
RUSTSEC-2026-0319
  • crates.io/anymap2
anymap2 is unmaintained 12 hours ago
  • No fix available
RUSTSEC-2026-0320
  • crates.io/wasmtime-wasi-http
Wasmtime wasi:http implementation panics with a zero timeout supplied 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0321
  • crates.io/wasmtime-wasi
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption 12 hours ago
  • Fix available
  • Severity - 4.0 (Medium)
RUSTSEC-2026-0322
  • crates.io/wasmtime-wasi
Excessive allocated memory on the host when guests don't have stdio 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0323
  • crates.io/wasmtime-wasi
fd_readdir copies uninitialized struct padding into guest memory 12 hours ago
  • Fix available
  • Severity - 2.1 (Low)
RUSTSEC-2026-0324
  • crates.io/wasmtime-wasi
Guest can panic host through filesystem timestamp before the epoch on wasip3 12 hours ago
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0325
  • crates.io/wasmtime
Mis-typed WebAssembly tag imports can lead to GC heap corruption 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0326
  • crates.io/wasmtime
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption 12 hours ago
  • Fix available
  • Severity - 5.7 (Medium)
RUSTSEC-2026-0327
  • crates.io/wasmtime
Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow 12 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-g4mp-vgx3-xrvm
  • crates.io/pageant
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows) 2 days ago
  • Fix available
  • Severity - 6.2 (Medium)
GHSA-35g8-35p8-c8fw
  • crates.io/russh
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey 2 days ago
  • Fix available
  • Severity - 6.5 (Medium)