Vendor Intelligence
rust
12 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.
CVE-2026-42559 · CVSS 8.8
rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
View CVE report →
CVE-2026-55441 · CVSS 8.6
Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
View CVE report →
CVE-2026-45137 · CVSS 8.2
Anchor: Program<'info, System> is not properly validated
View CVE report →
CVE-2026-49402 · CVSS 8.1
Deno: Command Injection via spawnSync & spawn on Windows
View CVE report →
CVE-2026-44471 · CVSS 7.8
gix-fs: Symlink prefix-reuse allows worktree escape during checkout
View CVE report →
CVE-2026-46545 · CVSS 7.5
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
View CVE report →
CVE-2026-53530 · CVSS 7.5
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
View CVE report →
CVE-2026-45310 · CVSS 7.4
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
View CVE report →
CVE-2026-45373 · CVSS 7.4
DeepSeek TUI has SSRF IPV6 bypass
View CVE report →
CVE-2026-35338 · CVSS 7.3
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
View CVE report →
CVE-2026-44983 · CVSS 7.3
smallbitvec: Integer overflow in safe API leads to heap buffer overflow
View CVE report →
CVE-2026-52834 · CVSS 7.3
jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow
View CVE report →