Catalog / Rust

Rust security advisories

All 6 advisories Rust has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
66 carry a CVE
critical
1
high
1
medium
3
low
1
Fix in the archive
4of 6 matched to a release
Oldest
30 Sep 20196.9 years ago

2 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2024-43402low

`std::process::Command` batch files argument escaping could be bypassed with trailing whitespace or periods

GHSA-2xg3-7mm6-98jjFixed in 1.81.0
CVE-2024-24576critical

`std::process::Command` did not properly escape arguments of batch files on Windows

GHSA-q455-m56c-85mhFixed in 1.77.2
CVE-2021-42574medium

rustc and bidirectional-override codepoints in source code

GHSA-rcv6-wg5m-24v6Fixed in 1.56.1, not held here
CVE-2019-16760medium

Cargo prior to Rust 1.26.0 may download the wrong dependency

GHSA-phjm-8x66-qw4r