Skip to content
All tracked CVEs

Updated 14:01

2352 fixed in the last 30 days

Severity
CVEStatusSeveritySummaryDistributionFixed
FixedHighRUSTSEC-2026-0195: quick-xml NamespaceResolver::push unbounded allocations on many xmlns attributes cause OOMsecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0194: quick-xml default duplicate-attribute check is O(N^2), causing CPU DoS on large tagssecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0187: lopdf load_mem parses deeply nested PDF arrays/dicts with unbounded recursion, causing stack overflow DoSsecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0185: Non-contiguous stream fragments cause Assembler excessive buffering, enabling RecvStream memory exhaustionsecure-packages-rollingSep 6, 2026
FixedMediumRUSTSEC-2026-0068: tar-rs <=0.4.44 ignores PAX size override, causing cross-parser file size discrepanciessecure-packages-rollingSep 6, 2026
FixedMediumRUSTSEC-2026-0067: tar-rs <=0.4.44 symlink handling lets crafted tarballs chmod arbitrary directories outside extraction rootsecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0048: AWS-LC CRL DP matching bug allows revoked certificates to bypass validation with partitioned IDP CRLssecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0047: Improper signature validation in AWS-LC PKCS7_verify() enables unauthenticated bypass with Authenticated Attributessecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0046: AWS-LC PKCS7_verify certificate chain verification bypass for multiple signers (non-final); affects aws-lc-syssecure-packages-rollingSep 6, 2026
FixedMediumRUSTSEC-2026-0045: AWS-LC AES-CCM EVP CIPHER timing side-channel reveals authentication tag validitysecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0041: LZ4 lz4_flex block API offset validation flaw leaks uninitialized/prior buffer datasecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0037: Panic when parsing invalid QUIC transport parameters due to unwrap() callssecure-packages-rollingSep 6, 2026
FixedMediumRUSTSEC-2026-0009: RFC 2822 parsing permits stack exhaustion DoS via maliciously crafted, deprecated feature usagesecure-packages-rollingSep 6, 2026
FixedMediumRUSTSEC-2023-0071: Timing side-channel in rsa crate leaks private keys due to non-constant-time implementationsecure-packages-rollingSep 6, 2026
FixedHighGHSA-xwg4-73v4-xw9w: nanoid size integer overflow corrupts CSPRNG pool, returning deterministic 'u' IDs process-widesecure-packages-rollingSep 6, 2026
FixedLowGHSA-xwfj-jgwm-7wp5: tracing-subscriber vulnerable to ANSI escape injection, enabling terminal manipulation and potential exploitationsecure-packages-rollingSep 6, 2026
FixedHighGHSA-xvcm-6775-5m9r: Immutable.js Map/Set DoS from attacker-crafted key hash collisions and linear bucketssecure-packages-rollingSep 6, 2026
FixedMediumGHSA-xv59-967r-8726: openssl crate AES wrap-pad cipher updates mis-size buffers, enabling attacker-controlled heap corruptionsecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0245: sevenz-rust path traversal: decompress_impl allows extraction outside target directory via unchecked entry pathssecure-packages-26.05Sep 6, 2026
FixedHighGHSA-xpqw-6gx7-v673: SVGO entity expansion vulnerability: custom XML entities cause DoS and Node.js OOM crashessecure-packages-rollingSep 6, 2026
FixedMediumGHSA-xphf-cx8h-7q9g: Function returns reference into OpenSSL structure that OpenSSL may mutate unexpectedly, causing unsafety.secure-packages-rollingSep 6, 2026
FixedHighGHSA-xp3w-r5p5-63rr: X509Ref::ocsp_responders creates invalid &str for non-UTF-8 OCSP URLs, causing undefined behaviorsecure-packages-rollingSep 6, 2026
FixedLowGHSA-xmgf-hq76-4vx2: OpenSSL pre-3.x *_from_pem_callback length validation bug causes password buffer over-readsecure-packages-rollingSep 6, 2026
FixedLowGHSA-xgp8-3hg3-c2mh: Wildcard DNS incorrectly accepted under permitted subtree constraints, allowing outside-subtree namessecure-packages-rollingSep 6, 2026
FixedLowGHSA-xffm-g5w8-qvg7: ReDoS in @eslint/plugin-kit ConfigCommentParser#parseJSONLikeConfig from unanchored regexsecure-packages-rollingSep 6, 2026
FixedMediumGHSA-xcf7-rvmh-g6q4: Empty string argument causes OpenSSL to call strlen, reading arbitrary memory until NULsecure-packages-rollingSep 6, 2026
FixedMediumGHSA-x5fp-wj9c-mxmx: qs v6.15.3 bracket-key comma=true inputs bypass arrayLimit/throwOnLimitExceeded, enabling DoSsecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0195: quick-xml NsReader/NamespaceResolver unbounded heap from many namespace declarations, enabling attacker-triggered OOMsecure-packages-26.05Sep 6, 2026
FixedHighGHSA-x494-mj8g-cj27: DoS in gix-pack: truncated deltas panic, attacker-sized allocations cause OOMsecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0194: O(N^2) duplicate-attribute check in quick-xml, including NsReader, allows CPU DoSsecure-packages-26.05Sep 6, 2026
FixedHighGHSA-wwq9-3cpr-mm53: Borsh HashMap serialization non-canonical, order-dependent, lacking decode checks; risks consensus splitssecure-packages-rollingSep 6, 2026
FixedCriticalGHSA-wf6x-7x77-mvgw: Immutable.js merge/mergeDeep/mergeDeepWith and Map.toJS/toObject vulnerable to prototype pollutionsecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0189: rmcp Streamable HTTP server pre-1.4.0 missing Host validation allows DNS rebinding attackssecure-packages-26.05Sep 6, 2026
FixedMediumGHSA-w9m9-85wc-3x92: postcss-selector-parser toString uncontrolled recursion allows remote DoS (pre-6.1.3/7.1.1)secure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0187: lopdf::Document::load_mem unbounded recursion on nested PDF arrays/dicts; stack overflow DoSsecure-packages-26.05Sep 6, 2026
FixedMediumGHSA-w8wr-v893-vjvp: node-tar DoS: extracting PAX entry with all-digit path causes uncaught TypeErrorsecure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0185: Non-contiguous RecvStream fragments cause Assembler buffer bloat, risking memory exhaustion during ordered readssecure-packages-26.05Sep 6, 2026
FixedCriticalGHSA-w7jw-789q-3m8p: shell-quote quote() lacks .op validation; line terminators pass unescaped, enabling command injection via object tokenssecure-packages-rollingSep 6, 2026
FixedLowGHSA-w7fw-mjwx-w883: qs: comma option bypasses arrayLimit, enabling DoS by massive array allocationsecure-packages-rollingSep 6, 2026
FixedHighGHSA-w5hq-g745-h8pq: uuid v3/v5/v6 accept out-of-range buf/offset, causing silent partial writessecure-packages-rollingSep 6, 2026
FixedHighGHSA-w3rx-r6r6-pgpr: image-size <=2.0.2 ICNS parser DoS blocks Node.js event loop via zero-length entrysecure-packages-rollingSep 6, 2026
FixedMediumGHSA-w2qp-rph6-63g4: Fastify <5.12.1 validates coerced root primitives but exposes uncoerced body to handlerssecure-packages-rollingSep 6, 2026
FixedHighGHSA-vxpw-j846-p89q: Undici WebSocket lacks fragment count limit, enabling memory exhaustion DoS since 6.17.0secure-packages-rollingSep 6, 2026
FixedHighGHSA-vw5v-4f2q-w9xf: aws-lc-sys PKCS7_verify certificate chain bypass with multiple signers (0.24.0–<0.38.0)secure-packages-rollingSep 6, 2026
FixedHighGHSA-vvp9-7p8x-rfvv: lz4_flex block decompression leaks uninitialized or previous buffer data due to invalid offset handlingsecure-packages-rollingSep 6, 2026
FixedHighGHSA-vmh5-mc38-953g: Undici ProxyAgent drops requestTls with SOCKS5, bypassing custom TLS settings and CA pinningsecure-packages-rollingSep 6, 2026
FixedMediumGHSA-vmf3-w455-68vh: node-tar PAX size applied to L/K/x headers causes parser desync, interpretation differentialsecure-packages-rollingSep 6, 2026
FixedMediumGHSA-v6wh-96g9-6wx3: Windows UNC path handling in launch-editor leaks NTLMv2 hashes to attacker SMB serverssecure-packages-rollingSep 6, 2026
FixedLowGHSA-v6h2-p8h4-qcjw: Remote ReDoS in juliangruber brace-expansion expand() from inefficient regex; affects <=4.0.0secure-packages-rollingSep 6, 2026
FixedHighRUSTSEC-2026-0103: thin-vec IntoIter::drop and clear on panic trigger double free/UAF memory corruption via safe Rustsecure-packages-26.05Sep 6, 2026

Contact sales

Provide us with some basic details and we'll follow up with you about , usually within one business day.

We'll only use this to get back to you. See our privacy policy (opens in a new tab). This site is protected by reCAPTCHA and the Google Privacy Policy (opens in a new tab) and Terms of Service (opens in a new tab) apply.