Vendor Intelligence

rust

12 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-42559 · CVSS 8.8

rmcp Streamable HTTP server transport has a DNS rebinding vulnerability

View CVE report →
CVE-2026-55441 · CVSS 8.6

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

View CVE report →
CVE-2026-45137 · CVSS 8.2

Anchor: Program<'info, System> is not properly validated

View CVE report →
CVE-2026-49402 · CVSS 8.1

Deno: Command Injection via spawnSync & spawn on Windows

View CVE report →
CVE-2026-44471 · CVSS 7.8

gix-fs: Symlink prefix-reuse allows worktree escape during checkout

View CVE report →
CVE-2026-46545 · CVSS 7.5

nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item

View CVE report →
CVE-2026-53530 · CVSS 7.5

ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)

View CVE report →
CVE-2026-45310 · CVSS 7.4

DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool

View CVE report →
CVE-2026-45373 · CVSS 7.4

DeepSeek TUI has SSRF‌ IPV6 bypass

View CVE report →
CVE-2026-35338 · CVSS 7.3

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

View CVE report →
CVE-2026-44983 · CVSS 7.3

smallbitvec: Integer overflow in safe API leads to heap buffer overflow

View CVE report →
CVE-2026-52834 · CVSS 7.3

jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow

View CVE report →