Security Advisories
Browse security advisories and track which Dependabot PRs address them.
37,272
Total Advisories
3,470
With Dependabot PRs
4,824
Critical Severity
13,193
High Severity
microsandbox: Secret values exposed in world-readable process arguments
GHSA-m8f5-rh7h-vgg3 CVE-2026-61670 MODERATE about 16 hours ago
## Summary
When the SDK spawns a sandbox, the `msb sandbox` child process receives the full network configuration as an inline `--network-config <...
cargo
No PRs yet
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
GHSA-4rf6-qx84-q9fv CVE-2026-68537 HIGH 6 days ago
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that
processes input supplied by many tenants. In versions prior to 0.26.0, a
c...
cargo
No PRs yet
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
GHSA-j5cx-ph8g-95v3 CVE-2026-68523 HIGH 6 days ago
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that
processes input supplied by many tenants. In versions prior to 0.19.0, a
b...
cargo
No PRs yet
RMCP: Custom HTTP headers leak to cross-origin redirect targets
GHSA-9g45-5xwm-f3wc CVE-2026-64684 MODERATE 6 days ago
## Summary
The `rmcp` crate's `StreamableHttpClientTransport` forwards caller-supplied custom HTTP headers (such as `X-API-Key`, `X-Auth-Token`, `...
cargo
No PRs yet
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
GHSA-9pj6-vhgr-3mwh CVE-2026-63128 HIGH 7 days ago
### Summary
An unauthenticated remote attacker can leak one entry per HTTP request out of the in-memory session table of `LocalSessionManager` by ...
cargo
No PRs yet
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
GHSA-33f5-2c5q-wgwj CVE-2026-63127 HIGH 7 days ago
### Summary
The `rmcp` library does not validate the `resource` parameter in OAuth Protected Resource metadata (RFC 9728), allowing a malicious MCP...
cargo
No PRs yet
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
GHSA-5hq8-qhww-jm7q CVE-2026-61544 HIGH 8 days ago
### Summary
`libp2p-quic` can panic on an inbound QUIC handshake if a malicious peer presents a valid, short lived libp2p TLS certificate and dela...
cargo
No PRs yet
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
GHSA-m3wp-48jr-vr4g HIGH 13 days ago
## Unbounded Remote Media Fetch and Video Frame Expansion DoS
### Summary
The `POST /v1/chat/completions` endpoint in mistral.rs fetches attacker-...
cargo
No PRs yet
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
GHSA-wfgq-w7cq-qj7j HIGH 13 days ago
### Summary
mistral.rs fetches any request-supplied image/audio URL with no host or IP validation, and opens arbitrary local files (a `file://` URL...
cargo
No PRs yet
gix-sec safe.directory protections absent for elevated administrators
GHSA-7rhf-42qf-vrvc CVE-2025-24890 MODERATE 14 days ago
### Summary
In a process run with full administrative rights on Windows, `gix-sec` wrongly treats all locations as trusted, leading to the executi...
cargo
No PRs yet
SWC HTML minifier may allow script element breakout when minifying embedded JSON
GHSA-5qr2-v392-m9g8 CVE-2026-72925 MODERATE 15 days ago
## Impact
`@swc/html` minifies JSON contained in `script` elements such as
`application/json` and `application/ld+json` by parsing and serializing...
cargo
npm
No PRs yet
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
GHSA-66r2-5gwj-gxm2 CVE-2026-63733 MODERATE 19 days ago
A `PERMISSIONS ... WHERE` clause is evaluated with permission enforcement disabled, so it can't recurse into its own checks. But the clause could a...
cargo
No PRs yet
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
GHSA-848m-r628-vrxw CVE-2026-63735 HIGH 19 days ago
An authenticated user scoped to one namespace/database could invoke a custom API (`DEFINE API`) belonging to a different namespace/database, reachi...
cargo
No PRs yet
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
GHSA-gx45-xrj5-g6c4 CVE-2026-75911 HIGH 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
GHSA-wrj3-vj8c-784f CVE-2026-75858 HIGH 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
GHSA-c6mw-8xh8-gpq6 CVE-2026-75912 HIGH 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
GHSA-6v2g-fpxh-pmmh CVE-2026-75856 CRITICAL 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
GHSA-h539-c7r8-3xq4 CVE-2026-75915 HIGH 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
GHSA-7j5w-7r7x-9v27 CVE-2026-75913 HIGH 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
GHSA-g29h-pfmp-qp9r CVE-2026-75857 HIGH 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
GHSA-62f5-cp2p-vq95 CVE-2026-75859 HIGH 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
GHSA-w7wx-5q49-r59w CVE-2026-75914 HIGH 19 days ago
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Vers...
cargo
npm
No PRs yet
SurrealDB allows bypass of deny-net flags via DNS resolution
GHSA-m3c3-78fh-w3w7 CVE-2025-71390 MODERATE 19 days ago
SurrealDB offers http functions that can access external network endpoints. A typical, albeit [not recommended ](https://surrealdb.com/docs/surreal...
cargo
No PRs yet
Hurl: Cookies in Cookies section leak when redirecting to a different host
GHSA-7w2g-9mf9-324m CVE-2026-63481 MODERATE 21 days ago
## The Bug
Hurl <= 8.0.1 lets you define cookies two ways in a .hurl file:
1. As a raw Cookie: header in the [Header]/headers area
2. In a dedica...
cargo
No PRs yet
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
GHSA-f9qc-qg88-7pq5 CVE-2026-55407 MODERATE 26 days ago
The `decode_unknown_field` function in buffa's protobuf decoder allocated heap memory in proportion to untrusted input (unknown fields in the seria...
cargo
1
Dependabot PRs
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
GHSA-9pwq-gcrx-wghh CVE-2026-55406 MODERATE 26 days ago
A soundness bug in `buffa`'s `OwnedView<V>` allowed safe Rust code to trigger a use-after-free. The `OwnedView::decode` constructor transmuted a bo...
cargo
No PRs yet
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS
GHSA-gpwf-4h98-v82q CVE-2026-54788 HIGH 26 days ago
### Impact
Datadog tracing libraries that implement W3C Trace Context (`tracecontext`) propagation parse the incoming `tracestate` header without e...
cargo
No PRs yet
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
GHSA-2vh6-hw4j-32ww MODERATE 26 days ago
### Summary
`gix-packetline` panics when it receives a side-band packet line that contains only the band-id byte with an empty payload. A malicious...
cargo
No PRs yet
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
GHSA-3p27-qvp9-27qf CVE-2026-54786 LOW 28 days ago
### Impact
Wasmtime's native implementation of WASIp1 suffers from a leak in the `fd_renumber` function where the file descriptor being renumbered...
cargo
1
Dependabot PRs
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
GHSA-p7x2-g5cq-fhmq CVE-2026-55663 MODERATE 29 days ago
### Summary
mediasoup's built-in SCTP stack (introduced in v3.20.0) authenticates SCTP state cookies using only hardcoded magic byte sequences rat...
cargo
npm
No PRs yet
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
GHSA-fx4f-mhw4-qm7j MODERATE 30 days ago
When using the affected versions of the `vibeio-http` crate, an attacker could craft a malicious HTTP/1.x request with a large chunk length (betwee...
cargo
No PRs yet
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
GHSA-3gjw-f78c-vvpw MODERATE 30 days ago
A malicious or compromised server can send a row containing fewer fields than
its row description declares columns. Reading one of the missing colu...
cargo
No PRs yet
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
GHSA-rgqc-3x5p-6gwg MODERATE 30 days ago
A malicious or compromised server can return a binary `hstore` value with an
invalid internal length field, causing the client to panic while decod...
cargo
No PRs yet
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
GHSA-5x78-73v4-xg6w HIGH 30 days ago
A malicious, compromised, or man-in-the-middle server can supply an arbitrarily
large SCRAM-SHA-256 PBKDF2 iteration count during authentication. T...
cargo
No PRs yet
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
GHSA-mc9m-6fm9-pghc MODERATE about 1 month ago
A race condition in kcl-lib can result in a use-after-free when accessing environments concurrently. During Vec reallocation, the previous buffer c...
cargo
pypi
No PRs yet
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
GHSA-jgvr-6x5w-hx5w MODERATE about 1 month ago
### Impact
Feeding a KCL program that wraps an expression in deep, unnecessary parentheses triggers the parser’s recursive `expression` -> `unneces...
cargo
pypi
No PRs yet
block_buffer: panic corrupts inline buffer position
GHSA-qwgh-2vcv-g2f7 MODERATE about 1 month ago
### Summary
A caught panic may leave the cursor position of `EagerBuffer` or `ReadBuffer` in a corrupted state; this in turn allows out-of-bounds ...
cargo
No PRs yet
Triton VM Soundness Vulnerability due to Missing Constraint
GHSA-vjf8-9fx6-mv6x MODERATE about 1 month ago
The instruction `sponge_absorb_mem` Triton VM fails to verify that hashed values come from the claimed memory location. Malicious provers can subst...
cargo
No PRs yet
s2n-quic has excessive memory allocation
GHSA-9q54-f358-3fqf CVE-2026-10740 MODERATE about 1 month ago
s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sen...
cargo
No PRs yet
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
GHSA-8rw6-p7m8-63jp CVE-2026-63740 MODERATE about 1 month ago
A `SELECT` permission defined on an array element (`DEFINE FIELD field.* … PERMISSIONS FOR select …`) is not enforced correctly for `RECORD` users....
cargo
No PRs yet
nimiq-blockchain: Validity store off by one error
GHSA-3763-qp59-59vf CVE-2026-46369 HIGH about 1 month ago
### Impact
The validity store treats a transaction with stored `block_number = X` as "in window" only when `X > last_bn - transaction_validity_wind...
cargo
No PRs yet
Russh: Channel-scoped server callbacks can be reached without an open channel
GHSA-m65r-rprj-r5rg CVE-2026-68930 MODERATE about 2 months ago
There is a server-side channel state issue in `russh`.
After a client is authenticated, `russh` can dispatch channel-scoped handler callbacks for ...
cargo
13
Dependabot PRs
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
GHSA-3whf-vgf2-9w6g MODERATE about 2 months ago
### Summary
`NonFinalizedState::handle_reorg` is a recursive, unbounded async function that traverses parent blocks until it finds a common ancesto...
cargo
No PRs yet
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
GHSA-6xx4-9wp6-65p7 MODERATE about 2 months ago
### Impact
`skilo add` installs a skill by recursively copying the skill directory into the
target skills directory. The copy routine (`copy_dir_a...
cargo
No PRs yet
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
GHSA-hc4m-q9jh-xw4j MODERATE about 2 months ago
## Summary
Registry-installed nono packs are expected to be verified from local provenance metadata before they are used. Two files are relevant:
...
cargo
No PRs yet
lettre has TLS hostname verification disabled when using Boring TLS backend
GHSA-4pj9-g833-qx53 CVE-2026-46428 CRITICAL about 2 months ago
### Summary
An inverted-boolean bug in lettre's `boring-tls` integration silently
disables TLS hostname verification for callers using the default ...
cargo
No PRs yet
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA-jvxp-qmx7-gjpx CVE-2026-16756 HIGH 2 months ago
## Summary
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, pow...
cargo
No PRs yet
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
GHSA-2625-rw7m-5q5x LOW 2 months ago
## Summary
`hubuum_client` diagnostics can expose sensitive request, response, import/export, task, delivery, or server-provided data when applica...
cargo
No PRs yet
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
GHSA-qqc3-94qv-7fw3 MODERATE 2 months ago
## Summary
When an application configures hubuum_client with ClientBuilder::with_transport, several client operations still use the built-in reqwe...
cargo
No PRs yet
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-f45q-w629-wr25 MODERATE 2 months ago
## Impact
The built-in async and blocking clients used reqwest's default redirect policy. `BaseUrl` constrains the initial request to the configur...
cargo
No PRs yet