← All tracked CVEs
Updated 14:01
2352 fixed in the last 30 days
| CVE | Status | Severity | Summary | Distribution | Fixed |
|---|---|---|---|---|---|
| Fixed | High | RUSTSEC-2026-0195: quick-xml NamespaceResolver::push unbounded allocations on many xmlns attributes cause OOM | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0194: quick-xml default duplicate-attribute check is O(N^2), causing CPU DoS on large tags | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0187: lopdf load_mem parses deeply nested PDF arrays/dicts with unbounded recursion, causing stack overflow DoS | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0185: Non-contiguous stream fragments cause Assembler excessive buffering, enabling RecvStream memory exhaustion | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0068: tar-rs <=0.4.44 ignores PAX size override, causing cross-parser file size discrepancies | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0067: tar-rs <=0.4.44 symlink handling lets crafted tarballs chmod arbitrary directories outside extraction root | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0048: AWS-LC CRL DP matching bug allows revoked certificates to bypass validation with partitioned IDP CRLs | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0047: Improper signature validation in AWS-LC PKCS7_verify() enables unauthenticated bypass with Authenticated Attributes | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0046: AWS-LC PKCS7_verify certificate chain verification bypass for multiple signers (non-final); affects aws-lc-sys | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0045: AWS-LC AES-CCM EVP CIPHER timing side-channel reveals authentication tag validity | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0041: LZ4 lz4_flex block API offset validation flaw leaks uninitialized/prior buffer data | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0037: Panic when parsing invalid QUIC transport parameters due to unwrap() calls | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2026-0009: RFC 2822 parsing permits stack exhaustion DoS via maliciously crafted, deprecated feature usage | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | RUSTSEC-2023-0071: Timing side-channel in rsa crate leaks private keys due to non-constant-time implementation | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-xwg4-73v4-xw9w: nanoid size integer overflow corrupts CSPRNG pool, returning deterministic 'u' IDs process-wide | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Low | GHSA-xwfj-jgwm-7wp5: tracing-subscriber vulnerable to ANSI escape injection, enabling terminal manipulation and potential exploitation | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-xvcm-6775-5m9r: Immutable.js Map/Set DoS from attacker-crafted key hash collisions and linear buckets | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xv59-967r-8726: openssl crate AES wrap-pad cipher updates mis-size buffers, enabling attacker-controlled heap corruption | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0245: sevenz-rust path traversal: decompress_impl allows extraction outside target directory via unchecked entry paths | secure-packages-26.05 | Sep 6, 2026 | |
| Fixed | High | GHSA-xpqw-6gx7-v673: SVGO entity expansion vulnerability: custom XML entities cause DoS and Node.js OOM crashes | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xphf-cx8h-7q9g: Function returns reference into OpenSSL structure that OpenSSL may mutate unexpectedly, causing unsafety. | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-xp3w-r5p5-63rr: X509Ref::ocsp_responders creates invalid &str for non-UTF-8 OCSP URLs, causing undefined behavior | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Low | GHSA-xmgf-hq76-4vx2: OpenSSL pre-3.x *_from_pem_callback length validation bug causes password buffer over-read | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Low | GHSA-xgp8-3hg3-c2mh: Wildcard DNS incorrectly accepted under permitted subtree constraints, allowing outside-subtree names | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Low | GHSA-xffm-g5w8-qvg7: ReDoS in @eslint/plugin-kit ConfigCommentParser#parseJSONLikeConfig from unanchored regex | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | GHSA-xcf7-rvmh-g6q4: Empty string argument causes OpenSSL to call strlen, reading arbitrary memory until NUL | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | GHSA-x5fp-wj9c-mxmx: qs v6.15.3 bracket-key comma=true inputs bypass arrayLimit/throwOnLimitExceeded, enabling DoS | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0195: quick-xml NsReader/NamespaceResolver unbounded heap from many namespace declarations, enabling attacker-triggered OOM | secure-packages-26.05 | Sep 6, 2026 | |
| Fixed | High | GHSA-x494-mj8g-cj27: DoS in gix-pack: truncated deltas panic, attacker-sized allocations cause OOM | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0194: O(N^2) duplicate-attribute check in quick-xml, including NsReader, allows CPU DoS | secure-packages-26.05 | Sep 6, 2026 | |
| Fixed | High | GHSA-wwq9-3cpr-mm53: Borsh HashMap serialization non-canonical, order-dependent, lacking decode checks; risks consensus splits | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Critical | GHSA-wf6x-7x77-mvgw: Immutable.js merge/mergeDeep/mergeDeepWith and Map.toJS/toObject vulnerable to prototype pollution | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0189: rmcp Streamable HTTP server pre-1.4.0 missing Host validation allows DNS rebinding attacks | secure-packages-26.05 | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w9m9-85wc-3x92: postcss-selector-parser toString uncontrolled recursion allows remote DoS (pre-6.1.3/7.1.1) | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0187: lopdf::Document::load_mem unbounded recursion on nested PDF arrays/dicts; stack overflow DoS | secure-packages-26.05 | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w8wr-v893-vjvp: node-tar DoS: extracting PAX entry with all-digit path causes uncaught TypeError | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0185: Non-contiguous RecvStream fragments cause Assembler buffer bloat, risking memory exhaustion during ordered reads | secure-packages-26.05 | Sep 6, 2026 | |
| Fixed | Critical | GHSA-w7jw-789q-3m8p: shell-quote quote() lacks .op validation; line terminators pass unescaped, enabling command injection via object tokens | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Low | GHSA-w7fw-mjwx-w883: qs: comma option bypasses arrayLimit, enabling DoS by massive array allocation | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-w5hq-g745-h8pq: uuid v3/v5/v6 accept out-of-range buf/offset, causing silent partial writes | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-w3rx-r6r6-pgpr: image-size <=2.0.2 ICNS parser DoS blocks Node.js event loop via zero-length entry | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | GHSA-w2qp-rph6-63g4: Fastify <5.12.1 validates coerced root primitives but exposes uncoerced body to handlers | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-vxpw-j846-p89q: Undici WebSocket lacks fragment count limit, enabling memory exhaustion DoS since 6.17.0 | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-vw5v-4f2q-w9xf: aws-lc-sys PKCS7_verify certificate chain bypass with multiple signers (0.24.0–<0.38.0) | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-vvp9-7p8x-rfvv: lz4_flex block decompression leaks uninitialized or previous buffer data due to invalid offset handling | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | GHSA-vmh5-mc38-953g: Undici ProxyAgent drops requestTls with SOCKS5, bypassing custom TLS settings and CA pinning | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | GHSA-vmf3-w455-68vh: node-tar PAX size applied to L/K/x headers causes parser desync, interpretation differential | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Medium | GHSA-v6wh-96g9-6wx3: Windows UNC path handling in launch-editor leaks NTLMv2 hashes to attacker SMB servers | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | Low | GHSA-v6h2-p8h4-qcjw: Remote ReDoS in juliangruber brace-expansion expand() from inefficient regex; affects <=4.0.0 | secure-packages-rolling | Sep 6, 2026 | |
| Fixed | High | RUSTSEC-2026-0103: thin-vec IntoIter::drop and clear on panic trigger double free/UAF memory corruption via safe Rust | secure-packages-26.05 | Sep 6, 2026 |