rust-lang
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 41 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 9, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Crates in third party registries can override the cached source of other crates
Cargo can be coerced to share credentials between registries
zip Vulnerable to Incorrect Path Canonicalization During Archive Extraction, Leading to Arbitrary File Write
Rust OS Command Injection/Argument Injection vulnerability
Command injection vulnerability in programing languages on Microsoft Windows operating system.
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels
Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports
Cargo not respecting umask when extracting crate archives
Cargo did not verify SSH host keys
Monitor rust-lang in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.