crates-io
OSS Librariespackage-ecosystem
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting crates-io.
- GHSA-m3wp-48jr-vr4g mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
- GHSA-wfgq-w7cq-qj7jmistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
- GHSA-2vh6-hw4j-32wwgix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
- GHSA-fx4f-mhw4-qm7jvibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
- GHSA-3gjw-f78c-vvpwtokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
- GHSA-rgqc-3x5p-6gwgpostgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
- GHSA-5x78-73v4-xg6wpostgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
- GHSA-mc9m-6fm9-pghcZoo Design Studio: Memory-corruption in memory handling of lib-kcl
- GHSA-jgvr-6x5w-hx5wZoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
- GHSA-qwgh-2vcv-g2f7block_buffer: panic corrupts inline buffer position
- GHSA-vjf8-9fx6-mv6xTriton VM Soundness Vulnerability due to Missing Constraint
- GHSA-8rw6-p7m8-63jpSurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
- GHSA-3whf-vgf2-9w6gzaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
- GHSA-6xx4-9wp6-65p7skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
- GHSA-hc4m-q9jh-xw4jnono-cli'scregistry pack verification can fail open when provenance metadata is absent