Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
OSV Rustsec π¦ is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| rustsec-2026-0327 | Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow | 2026-10-02T12:00:00Z | 2026-10-02T20:27:46Z |
| rustsec-2026-0326 | Rooting for GC values live across `try_call` may be missing, causing GC heap corruption | 2026-10-02T12:00:00Z | 2026-10-02T20:27:46Z |
| rustsec-2026-0325 | Mis-typed WebAssembly tag imports can lead to GC heap corruption | 2026-10-02T12:00:00Z | 2026-10-02T20:27:46Z |
| rustsec-2026-0324 | Guest can panic host through filesystem timestamp before the epoch on wasip3 | 2026-10-02T12:00:00Z | 2026-10-02T20:27:46Z |
| rustsec-2026-0323 | fd_readdir copies uninitialized struct padding into guest memory | 2026-10-02T12:00:00Z | 2026-10-02T20:27:46Z |
| rustsec-2026-0322 | Excessive allocated memory on the host when guests don't have stdio | 2026-10-02T12:00:00Z | 2026-10-02T20:27:46Z |
| rustsec-2026-0321 | WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption | 2026-10-02T12:00:00Z | 2026-10-02T20:27:46Z |
| rustsec-2026-0320 | Wasmtime wasi:http implementation panics with a zero timeout supplied | 2026-10-02T12:00:00Z | 2026-10-02T20:27:46Z |
| rustsec-2026-0319 | anymap2 is unmaintained | 2026-10-02T12:00:00Z | 2026-10-02T08:58:33Z |
| rustsec-2026-0318 | Sending custom to-device messages may panics | 2026-09-29T12:00:00Z | 2026-10-01T20:25:27Z |
| rustsec-2026-0317 | A 512-byte workbook can provoke a multi-gigabyte allocation and abort the process | 2026-09-29T12:00:00Z | 2026-10-01T07:31:41Z |
| rustsec-2026-0311 | Stack overflow on deeply nested LaTeX input | 2026-09-27T12:00:00Z | 2026-09-28T08:34:35Z |
| rustsec-2026-0310 | Various panics, soundness and resource exhaustion issues | 2026-09-25T12:00:00Z | 2026-09-25T17:51:57Z |
| rustsec-2026-0316 | Dynamic record lifting can allocate beyond the hostcall fuel limit | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0315 | `call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0314 | Guest can panic host through filesystem datetime overflow | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0313 | Outgoing HTTP body write allows guest-driven host memory exhaustion | 2026-09-24T12:00:00Z | 2026-09-29T07:32:15Z |
| rustsec-2026-0312 | Excluded iPAddress name constraints with an all-zero mask are not applied | 2026-09-24T12:00:00Z | 2026-09-28T09:30:11Z |
| rustsec-2026-0308 | Use-after-free in interned values and cached function results | 2026-09-24T12:00:00Z | 2026-09-24T14:38:19Z |
| rustsec-2026-0307 | `uncbv`: archive extraction is vulnerable to path traversal (zip-slip) | 2026-09-23T12:00:00Z | 2026-09-24T08:52:17Z |
| rustsec-2026-0305 | Use-after-free when XML includes have duplicated entities | 2026-09-23T12:00:00Z | 2026-10-01T19:14:05Z |
| rustsec-2026-0303 | `stack-graphs` is archived and unmaintained | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0302 | `stack-graphs` C API exports are safe `extern "C"` functions | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0301 | Double free in `StackVec::retain` when a predicate or element `Drop` panics | 2026-09-22T12:00:00Z | 2026-09-22T20:47:48Z |
| rustsec-2026-0299 | `owned-alloc` is unmaintained | 2026-09-22T12:00:00Z | 2026-09-22T07:35:37Z |
| rustsec-2026-0304 | Finished streaming calls keep reading a stalled request body indefinitely | 2026-09-21T12:00:00Z | 2026-09-23T07:36:54Z |
| rustsec-2026-0296 | `unzip` is unmaintained | 2026-09-21T12:00:00Z | 2026-09-21T15:17:02Z |
| rustsec-2026-0293 | Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics | 2026-09-21T12:00:00Z | 2026-09-21T09:10:46Z |
| rustsec-2026-0309 | `SinglyLinkedList::remove` dereferences a null link | 2026-09-20T12:00:00Z | 2026-09-25T17:51:57Z |
| rustsec-2026-0306 | `hex_decode_unchecked` AVX2 path reads past `src` | 2026-09-20T12:00:00Z | 2026-09-23T14:07:49Z |