Security Advisories
Browse security advisories and track which Dependabot PRs address them.
34,981
Total Advisories
3,105
With Dependabot PRs
4,555
Critical Severity
12,244
High Severity
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA-jvxp-qmx7-gjpx CVE-2026-16756 HIGH 3 days ago
## Summary
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, pow...
cargo
No PRs yet
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
GHSA-2625-rw7m-5q5x LOW 3 days ago
## Summary
`hubuum_client` diagnostics can expose sensitive request, response, import/export, task, delivery, or server-provided data when applica...
cargo
No PRs yet
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
GHSA-qqc3-94qv-7fw3 MODERATE 3 days ago
## Summary
When an application configures hubuum_client with ClientBuilder::with_transport, several client operations still use the built-in reqwe...
cargo
No PRs yet
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-f45q-w629-wr25 MODERATE 3 days ago
## Impact
The built-in async and blocking clients used reqwest's default redirect policy. `BaseUrl` constrains the initial request to the configur...
cargo
No PRs yet
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
GHSA-g9hv-x236-4qp3 MODERATE 3 days ago
### Summary
A malicious SSH server can crash a `russh` client session with a single
malformed key-exchange reply, causing a pre-authentication Deni...
cargo
No PRs yet
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
GHSA-cqjc-rmpq-xprq MODERATE 3 days ago
## Summary
A post-authentication denial-of-service panic in `russh` 0.62.2 (commit
`c4be19f1915c8682f4615c3fd50008512b474491`, current default bra...
cargo
No PRs yet
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
GHSA-5xvq-cp9x-6p6r MODERATE 3 days ago
A pre-authentication denial-of-service panic in `russh` 0.62.2 (commit
`c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as...
cargo
No PRs yet
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-4w2j-m93h-cj5j HIGH 3 days ago
## Summary
The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-...
cargo
No PRs yet
Prompty: Arbitrary file read via file reference expansion
GHSA-wxhm-2mq7-7697 CVE-2026-53598 HIGH 10 days ago
## Summary
Prompty loaders expanded `${file:...}` references in `.prompty` frontmatter without enforcing that the resolved path stayed within an au...
cargo
npm
nuget
+1 more
No PRs yet
nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof
GHSA-5rg2-xv9j-gv5p CVE-2026-54542 LOW 11 days ago
### Impact
A malicious peer acting as a state-sync source can crash a syncing node with a crafted `TrieChunk` whose proof contains a `TrieNodeChil...
cargo
No PRs yet
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
GHSA-46wq-28cx-mhw4 CVE-2026-54541 LOW 11 days ago
### Impact
A malicious peer acting as a state-sync source can crash a syncing node by sending a crafted `TrieChunk` whose proof contains two `Trie...
cargo
No PRs yet
Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
GHSA-ggxf-9f6j-w742 MODERATE 11 days ago
Diesel allows loading a SQLite database from a byte buffer, represented as `&[u8]`, at runtime via the `SqliteConnection::deserialize_readonly_data...
cargo
No PRs yet
serde_with: KeyValueMap serialization panics on empty sequence or map entries
GHSA-7gcf-g7xr-8hxj MODERATE 12 days ago
### Summary
The public `KeyValueMap` serializer assumes that each mapped element has at least one field or item to use as the map key, but it subt...
cargo
4
Dependabot PRs
Wasmtime: Memory leak in C API with `externref` and `anyref` types
GHSA-vvp9-h8p2-xwfc CVE-2025-61670 LOW 13 days ago
### Impact
Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. T...
cargo
pypi
No PRs yet
`exploration` was removed from crates.io for malicious code
GHSA-99j7-fhr2-xfj4 CRITICAL 17 days ago
A method within the `exploration` crate attempted to download and execute a payload from a remote site.
The malicious crate had 1 version publishe...
cargo
No PRs yet
Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search
GHSA-2ppx-66jv-wpw5 CVE-2026-54136 MODERATE 17 days ago
### Summary
A resource-scoped API token can read script contents outside its allowed path scope via `GET /api/w/{workspace}/scripts/list_search`.
...
cargo
No PRs yet
Rattler vulnerable to package cache path traversal via conda package build string
GHSA-h672-p7h7-97v9 CVE-2026-53956 MODERATE 18 days ago
`rattler_cache` and `py-rattler` were vulnerable to package-cache path traversal when handling package metadata from conda channels.
During cache ...
cargo
pypi
No PRs yet
OneRingBuf has a Use After Free Vulnerability
GHSA-q95x-7g78-rccv MODERATE 19 days ago
Affected versions of `oneringbuf` exposed the obsolete `IntoRef::into_ref` method through the public `IntoRef` trait. For heap-backed ring buffers,...
cargo
No PRs yet
async-tar PAX extension-header desync enables tar entry/content smuggling
GHSA-35rm-7j9c-2f7m CVE-2026-53600 MODERATE 19 days ago
## Summary
`async-tar` v0.6.0 mis-applies a buffered PAX `size` extension to an intermediary
extension header (a GNU longname `L`, a GNU longlink ...
cargo
No PRs yet
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
GHSA-cwv4-h3j5-w3cf LOW 20 days ago
Resolved: https://github.com/plabayo/rama/commit/89ddff578fd78bbebec99482d7030f28c07757a3
## Summary
`plabayo/rama` contains a stored/reflected c...
cargo
No PRs yet
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
GHSA-4w5h-hx6r-28q7 CVE-2026-53531 MODERATE 20 days ago
### Summary
RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, wi...
cargo
No PRs yet
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
GHSA-4hgp-59h5-gvrj CVE-2026-53530 HIGH 20 days ago
### Summary
The public parser entrypoint `ratex_parser::parse(&str)` panics on the **9-byte** input `\verbéxé` (i.e. `\verb` followed by the non-A...
cargo
No PRs yet
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
GHSA-fqf6-gxhh-2xhw HIGH 20 days ago
`determine_backup_mode` in `src/uucore/src/lib/features/backup_control.rs` only checks `--backup`/`-b` and returns `BackupMode::None` when only `--...
cargo
No PRs yet
cut: -s ignored in -z -d '' newline-delimiter mode
GHSA-pmfc-4wjj-gmhx CVE-2026-35381 LOW 21 days ago
`cut` routes `-z -d ''` through a special newline-delimiter path that ignores the `-s` only-delimited flag, emitting whole undelimited records (plu...
cargo
No PRs yet
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
GHSA-r9hw-mj3w-phcq CVE-2026-35361 LOW 21 days ago
uutils calls `mknod` *before* setting the SELinux context (GNU uses `setfscreatecon` first, labeling atomically). If `set_selinux_security_context`...
cargo
No PRs yet
mkfifo: permissions of an existing file are changed after FIFO creation fails
GHSA-pmf6-rcx4-v53v CVE-2026-35341 HIGH 21 days ago
When `mkfifo()` fails (e.g. target already exists), the code shows an error but is missing a `continue;`, so it falls through to `fs::set_permissio...
cargo
No PRs yet
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
GHSA-ww9q-8r59-xv46 CVE-2026-54496 CRITICAL 21 days ago
### Summary
A soundness vulnerability in the variable-base scalar multiplication gadget of `halo2_gadgets` allowed a malicious prover to produce a...
cargo
No PRs yet
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
GHSA-p7h3-7q52-72w8 CVE-2026-35366 MODERATE 21 days ago
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitr...
cargo
No PRs yet
uucore: safe_traversal TOCTOU protection only enabled on Linux
GHSA-w6xc-g9qj-vp32 CVE-2026-35362 LOW 21 days ago
The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-des...
cargo
No PRs yet
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
GHSA-h444-6j9x-p8vh CVE-2026-35365 MODERATE 21 days ago
When moving directories across filesystems, uutils `mv` dereferences symlinks inside the tree, copying their targets as real files/dirs instead of ...
cargo
No PRs yet
cp: -R reads device nodes as streams, destroying device semantics
GHSA-8vrf-r662-2w2v CVE-2026-35358 MODERATE 21 days ago
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources ra...
cargo
No PRs yet
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
GHSA-89p7-7cq3-hhr2 CVE-2026-35363 MODERATE 21 days ago
`rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `....
cargo
No PRs yet
comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
GHSA-3wfc-mgpm-9rq6 CVE-2026-35347 MODERATE 21 days ago
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_...
cargo
No PRs yet
id: groups= computed from real GID instead of effective GID
GHSA-47c7-qrm7-mqw7 CVE-2026-35370 MODERATE 21 days ago
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effe...
cargo
No PRs yet
mkdir: -m exposes directory with umask perms before chmod (race window)
GHSA-mj6p-44ch-cq69 CVE-2026-35353 LOW 21 days ago
The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions...
cargo
No PRs yet
rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)
GHSA-7cr3-h577-g38j CVE-2026-35349 MODERATE 21 days ago
The `--preserve-root` check uses a path-string test (`path.has_root() && path.parent().is_none()`) rather than comparing device/inode. A symlink to...
cargo
No PRs yet
id: pretty-print uses effective GID instead of effective UID for name lookup
GHSA-xv5w-cw7x-72gj CVE-2026-35371 LOW 21 days ago
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The impleme...
cargo
No PRs yet
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
GHSA-p6rv-2qpm-fwvg CVE-2026-35369 MODERATE 21 days ago
`kill -1` is incorrectly parsed as a positional `pid = -1`; combined with the default SIGTERM this calls `kill(-1, SIGTERM)`, signaling nearly ever...
cargo
No PRs yet
install -D: symlink race in directory creation allows arbitrary file overwrite
GHSA-gwm6-q8ch-hcfr CVE-2026-35356 MODERATE 21 days ago
The `-D` path runs `fs::create_dir_all` on a pathname then later opens the destination via path-based `File::create`/`fs::copy`, neither anchored t...
cargo
No PRs yet
cut: -s (only-delimited) ignored when delimiter is a newline
GHSA-wv33-5pxh-r7j7 CVE-2026-35343 LOW 21 days ago
The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The ...
cargo
No PRs yet
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
GHSA-239g-2685-54x3 CVE-2026-35355 MODERATE 21 days ago
`copy_file` in `install/src/install.rs` removes the destination then recreates it by pathname via `File::create` / `fs::copy` without `O_EXCL`/`cre...
cargo
No PRs yet
ln: rejects non-UTF-8 source filenames in target-directory mode
GHSA-jcjr-rh8q-7xqf CVE-2026-35373 LOW 21 days ago
In target-directory forms (`ln SOURCE... DIRECTORY`), `ln` rejects source paths with non-UTF-8 filename bytes, while GNU accepts them. Breaks GNU c...
cargo
No PRs yet
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
GHSA-6gcw-w7cp-94g9 CVE-2026-35346 LOW 21 days ago
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses Strin...
cargo
No PRs yet
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
GHSA-2w8r-9xj7-69j5 CVE-2026-35342 LOW 21 days ago
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp w...
cargo
No PRs yet
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
GHSA-4x34-chg5-mwjj CVE-2026-35339 MODERATE 21 days ago
In `Chmoder::chmod()` the recursive branch overwrites the running result instead of accumulating it, so the exit code reflects only the *last* file...
cargo
No PRs yet
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
GHSA-4c7q-4928-8445 CVE-2026-35338 HIGH 21 days ago
`Chmoder::chmod()` only compares the literal argument against `Path::new("/")`, so the `--preserve-root` guard is bypassed by any path that *resolv...
cargo
No PRs yet
jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow
GHSA-5pmv-rx8r-wmv5 CVE-2026-52834 HIGH 25 days ago
### Summary
On 32-bit platforms, decoding a crafted image may lead to out-of-bounds writes due to integer overflow in length calculation.
### Det...
cargo
No PRs yet
jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow
GHSA-66m8-c62j-h6v5 MODERATE 25 days ago
### Summary
`jxl-oxide` exposes a public safe API that can construct an undersized `FrameBuffer` due to unchecked `usize` multiplication, which imm...
cargo
No PRs yet
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
GHSA-2v8p-fqpx-2q3w MODERATE 25 days ago
### Summary
Logic bug in `decode_simple_table_slow` may cause integer arithmetic overflow when decoding Modular image with certain kind of MA tree,...
cargo
No PRs yet
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
GHSA-63wg-wjjj-7cp8 CVE-2026-52829 HIGH 25 days ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node listens on the default `[::]` address on a ...
cargo
No PRs yet