CRITICAL9.8CVE-2021-31162In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics. >= 1.48.0, < 1.51.0-r2
CRITICAL9.1CVE-2021-29922library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address… from 0, < 1.52.1-r1
HIGH8.3CVE-2026-55200libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforc… from 0, < 1.96.1-r0
HIGH8.3An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.
from 0, < 1.56.1-r0
HIGH8.2In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be expose…
from 0, < 1.51.0-r2
HIGH8.1The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's s…
>= 1.34.0, < 1.34.2-r0
HIGH7.9Cargo not respecting umask when extracting crate archives
from 0, < 1.71.1-r0
HIGH7.5libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO hand…
from 0, < 1.96.1-r0
HIGH7.5Cargo prior to Rust 1.26.0 may download the wrong dependency
from 0, < 1.26.0-r0
MEDIUM6.5Cargo can be coerced to share credentials between registries
from 0, < 1.91.1-r2
MEDIUM6.5libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sf…
from 0, < 1.96.1-r0
MEDIUM6.5`unpack_in` can chmod arbitrary directories by following symlinks
from 0, < 1.78.0-r1
MEDIUM5.3Cargo crates in third party registries can override the cached source of other crates
from 0, < 1.91.1-r2
MEDIUM5.3Cargo did not verify SSH host keys
from 0, < 1.66.1-r0