Where
-Infinity
0

Vendor Risk Score

See how rust-lang compares to other vendors in security performance

View Risk Score →

Rust CargoCrates in third party registries can override the cached source of other crates

Risk 74
Severity
6.5
First published (updated )

Rust CargoCargo can be coerced to share credentials between registries

Risk 40
Severity
2.3
First published (updated )

rust-lang zipzip Vulnerable to Incorrect Path Canonicalization During Archive Extraction, Leading to Arbitrary File Write

Risk 51
Severity
7.3
EPSS
0.09%
First published (updated )

rust-lang RustRust OS Command Injection/Argument Injection vulnerability

Risk 76
Severity
8.8
First published (updated )

Nodejs Node.jsCommand injection vulnerability in programing languages on Microsoft Windows operating system.

Risk 61
Severity
9.8
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Fedoraproject FedoraRusts's `std::process::Command` did not properly escape arguments of batch files on Windows

Risk 93
Severity
10
First published (updated )

rust/rsaRustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels

Risk 36
Severity
5.9
First published (updated )

rust/cargoMalicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports

Risk 38
Severity
6.1
First published (updated )

ubuntu/cargoCargo not respecting umask when extracting crate archives

Risk 59
Severity
7.9
First published (updated )

rust/cargoCargo did not verify SSH host keys

Risk 36
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust/cargoExtracting malicious crates can fill the file system

Risk 38
Severity
6.5
First published (updated )

rust/cargoExtracting malicious crates can corrupt arbitrary files

Risk 60
Severity
8.1
First published (updated )

Fedoraproject FedoraRegular expression denial of service in Rust's regex crate

Risk 45
Severity
7.5
First published (updated )

Apple tvOSRace condition in std::fs::remove_dir_all in rustlang

Risk 48
Severity
7.3
First published (updated )

rust-lang Rustlibrary/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero chara…

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust-lang RustRace Condition

Risk 35
Severity
5.9
First published (updated )

Fedoraproject FedoraIn the standard library in Rust before 1.52.0, there is an optimization for joining strings that can…

Risk 54
Severity
8.2
First published (updated )

rust-lang RustRace Condition

Risk 35
Severity
5.9
First published (updated )

Fedoraproject FedoraDouble Free

Risk 86
Severity
9.8
First published (updated )

rust-lang RustBuffer Overflow

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust-lang RustIn the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem.…

Risk 43
Severity
7.5
First published (updated )

rust-lang RustDouble Free, Use After Free

Risk 86
Severity
9.8
First published (updated )

rust-lang RustBuffer Overflow

Risk 43
Severity
7.5
First published (updated )

Fedoraproject FedoraIn the standard library in Rust before 1.52.0, the Zip implementation has a panic safety issue. It c…

Risk 27
Severity
5.3
First published (updated )

Fedoraproject FedoraBuffer Overflow, Integer Overflow

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust-lang RustBuffer Overflow

Risk 43
Severity
7.5
First published (updated )

Fedoraproject FedoraBuffer Overflow

Risk 43
Severity
7.5
First published (updated )

rust-lang Async-h1 RustXSS

Risk 38
Severity
6.1
First published (updated )

rust-lang Mdbook RustXSS in mdBook's search page

Risk 53
Severity
8.2
First published (updated )

rust-lang Future-utils RustRace Condition

Risk 28
Severity
4.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203