Crate:     chrono
Version:   0.4.19
Title:     Potential segfault in `localtime_r` invocations
Date:      2020-11-10
ID:        RUSTSEC-2020-0159
URL:       https://rustsec.org/advisories/RUSTSEC-2020-0159
Solution:  Upgrade to >=0.4.20

Crate:     crossbeam-epoch
Version:   0.9.8
Title:     Invalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalid
Date:      2026-07-06
ID:        RUSTSEC-2026-0204
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0204
Solution:  Upgrade to >=0.9.20

Crate:     curve25519-dalek
Version:   3.2.1
Title:     Timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Date:      2024-06-18
ID:        RUSTSEC-2024-0344
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0344
Solution:  Upgrade to >=4.1.3

Crate:     ed25519-dalek
Version:   1.0.1
Title:     Double Public Key Signing Function Oracle Attack on `ed25519-dalek`
Date:      2022-06-11
ID:        RUSTSEC-2022-0093
URL:       https://rustsec.org/advisories/RUSTSEC-2022-0093
Solution:  Upgrade to >=2

Crate:     h2
Version:   0.3.13
Title:     Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Date:      2024-01-17
ID:        RUSTSEC-2024-0003
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0003
Solution:  Upgrade to ^0.3.24 OR >=0.4.2

Crate:     h2
Version:   0.3.13
Title:     Degradation of service in h2 servers with CONTINUATION Flood
Date:      2024-04-03
ID:        RUSTSEC-2024-0332
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0332
Solution:  Upgrade to ^0.3.26 OR >=0.4.4

Crate:     h2
Version:   0.3.13
Title:     Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Date:      2023-04-14
ID:        RUSTSEC-2023-0034
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0034
Solution:  Upgrade to >=0.3.17

Crate:     idna
Version:   0.2.3
Title:     `idna` accepts Punycode labels that do not produce any non-ASCII when decoded
Date:      2024-12-09
ID:        RUSTSEC-2024-0421
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0421
Solution:  Upgrade to >=1.0.0

Crate:     libgit2-sys
Version:   0.13.2+1.4.2
Title:     Memory corruption, denial of service, and arbitrary code execution in libgit2
Date:      2024-02-06
ID:        RUSTSEC-2024-0013
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0013
Severity:  8.6 (high)
Solution:  Upgrade to >=0.16.2

Crate:     libgit2-sys
Version:   0.13.2+1.4.2
Title:     git2 does not verify SSH keys by default
Date:      2023-01-20
ID:        RUSTSEC-2023-0003
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0003
Solution:  Upgrade to >=0.13.5, <0.14.0 OR >=0.14.2

Crate:     mio
Version:   0.8.3
Title:     Tokens for named pipes may be delivered after deregistration
Date:      2024-03-04
ID:        RUSTSEC-2024-0019
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0019
Solution:  Upgrade to >=0.8.11

Crate:     openssl
Version:   0.10.40
Title:     `openssl` `X509NameBuilder::build` returned object is not thread safe
Date:      2023-03-24
ID:        RUSTSEC-2023-0022
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0022
Solution:  Upgrade to >=0.10.48

Crate:     openssl
Version:   0.10.40
Title:     `openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
Date:      2023-03-24
ID:        RUSTSEC-2023-0023
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0023
Solution:  Upgrade to >=0.10.48

Crate:     openssl
Version:   0.10.40
Title:     `openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
Date:      2023-03-24
ID:        RUSTSEC-2023-0024
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0024
Solution:  Upgrade to >=0.10.48

Crate:     openssl
Version:   0.10.40
Title:     `openssl` `X509VerifyParamRef::set_host` buffer over-read
Date:      2023-06-20
ID:        RUSTSEC-2023-0044
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0044
Solution:  Upgrade to >=0.10.55

Crate:     openssl
Version:   0.10.40
Title:     `MemBio::get_buf` has undefined behavior with empty buffers
Date:      2024-07-21
ID:        RUSTSEC-2024-0357
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0357
Solution:  Upgrade to >=0.10.66

Crate:     openssl
Version:   0.10.40
Title:     ssl::select_next_proto use after free
Date:      2025-02-02
ID:        RUSTSEC-2025-0004
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0004
Solution:  Upgrade to >=0.10.70

Crate:     openssl
Version:   0.10.40
Title:     Use-After-Free in `Md::fetch` and `Cipher::fetch`
Date:      2025-04-04
ID:        RUSTSEC-2025-0022
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0022
Solution:  Upgrade to >=0.10.72

Crate:     openssl-src
Version:   111.20.0+1.1.1o
Title:     AES OCB fails to encrypt some bytes
Date:      2022-07-05
ID:        RUSTSEC-2022-0032
URL:       https://rustsec.org/advisories/RUSTSEC-2022-0032
Solution:  Upgrade to >=111.22, <300.0 OR >=300.0.9

Crate:     openssl-src
Version:   111.20.0+1.1.1o
Title:     X.400 address type confusion in X.509 `GeneralName`
Date:      2023-02-07
ID:        RUSTSEC-2023-0006
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0006
Solution:  Upgrade to >=111.25, <300.0 OR >=300.0.12

Crate:     openssl-src
Version:   111.20.0+1.1.1o
Title:     Timing Oracle in RSA Decryption
Date:      2023-02-07
ID:        RUSTSEC-2023-0007
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0007
Solution:  Upgrade to >=111.25, <300.0 OR >=300.0.12

Crate:     openssl-src
Version:   111.20.0+1.1.1o
Title:     Use-after-free following `BIO_new_NDEF`
Date:      2023-02-07
ID:        RUSTSEC-2023-0009
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0009
Solution:  Upgrade to >=111.25, <300.0 OR >=300.0.12

Crate:     openssl-src
Version:   111.20.0+1.1.1o
Title:     Double free after calling `PEM_read_bio_ex`
Date:      2023-02-07
ID:        RUSTSEC-2023-0010
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0010
Solution:  Upgrade to >=111.25, <300.0 OR >=300.0.12

Crate:     remove_dir_all
Version:   0.5.3
Title:     Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU)
Date:      2023-02-24
ID:        RUSTSEC-2023-0018
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0018
Solution:  Upgrade to >=0.8.0

Crate:     tar
Version:   0.4.38
Title:     `unpack_in` can chmod arbitrary directories by following symlinks
Date:      2026-03-19
ID:        RUSTSEC-2026-0067
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0067
Severity:  5.1 (medium)
Solution:  Upgrade to >=0.4.45

Crate:     tar
Version:   0.4.38
Title:     tar-rs incorrectly ignores PAX size headers if header size is nonzero
Date:      2026-03-19
ID:        RUSTSEC-2026-0068
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0068
Severity:  5.1 (medium)
Solution:  Upgrade to >=0.4.45

Crate:     time
Version:   0.3.9
Title:     Denial of Service via Stack Exhaustion
Date:      2026-02-05
ID:        RUSTSEC-2026-0009
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0009
Severity:  6.8 (medium)
Solution:  Upgrade to >=0.3.47

Crate:     tokio
Version:   1.18.2
Title:     reject_remote_clients Configuration corruption
Date:      2023-01-04
ID:        RUSTSEC-2023-0001
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0001
Solution:  Upgrade to >=1.18.4, <1.19.0 OR >=1.20.3, <1.21.0 OR >=1.23.1

Crate:     adler
Version:   1.0.2
Warning:   unmaintained
Title:     adler crate is unmaintained, use adler2 instead
Date:      2025-09-05
ID:        RUSTSEC-2025-0056
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0056

Crate:     ansi_term
Version:   0.12.1
Warning:   unmaintained
Title:     ansi_term is Unmaintained
Date:      2021-08-18
ID:        RUSTSEC-2021-0139
URL:       https://rustsec.org/advisories/RUSTSEC-2021-0139

Crate:     atty
Version:   0.2.14
Warning:   unmaintained
Title:     `atty` is unmaintained
Date:      2024-09-25
ID:        RUSTSEC-2024-0375
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0375

Crate:     crypto-hash
Version:   0.3.4
Warning:   unmaintained
Title:     crypto-hash crate is unmaintained
Date:      2025-09-08
ID:        RUSTSEC-2025-0060
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0060

Crate:     instant
Version:   0.1.12
Warning:   unmaintained
Title:     `instant` is unmaintained
Date:      2024-09-01
ID:        RUSTSEC-2024-0384
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0384

Crate:     proc-macro-error
Version:   1.0.4
Warning:   unmaintained
Title:     proc-macro-error is unmaintained
Date:      2024-09-01
ID:        RUSTSEC-2024-0370
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0370

Crate:     serde_cbor
Version:   0.11.2
Warning:   unmaintained
Title:     serde_cbor is unmaintained
Date:      2021-08-15
ID:        RUSTSEC-2021-0127
URL:       https://rustsec.org/advisories/RUSTSEC-2021-0127

Crate:     structopt
Version:   0.3.26
Warning:   unmaintained
Title:     `structopt` is in maintenance mode
Date:      2022-02-08
ID:        RUSTSEC-2022-0104
URL:       https://rustsec.org/advisories/RUSTSEC-2022-0104

Crate:     term_size
Version:   0.3.2
Warning:   unmaintained
Title:     `term_size` is unmaintained; use `terminal_size` instead
Date:      2020-11-03
ID:        RUSTSEC-2020-0163
URL:       https://rustsec.org/advisories/RUSTSEC-2020-0163

Crate:     unic-char-property
Version:   0.9.0
Warning:   unmaintained
Title:     `unic-char-property` is unmaintained
Date:      2025-10-18
ID:        RUSTSEC-2025-0081
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0081

Crate:     unic-char-range
Version:   0.9.0
Warning:   unmaintained
Title:     `unic-char-range` is unmaintained
Date:      2025-10-18
ID:        RUSTSEC-2025-0075
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0075

Crate:     unic-common
Version:   0.9.0
Warning:   unmaintained
Title:     `unic-common` is unmaintained
Date:      2025-10-18
ID:        RUSTSEC-2025-0080
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0080

Crate:     unic-segment
Version:   0.9.0
Warning:   unmaintained
Title:     `unic-segment` is unmaintained
Date:      2025-10-18
ID:        RUSTSEC-2025-0074
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0074

Crate:     unic-ucd-segment
Version:   0.9.0
Warning:   unmaintained
Title:     `unic-ucd-segment` is unmaintained
Date:      2025-10-18
ID:        RUSTSEC-2025-0104
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0104

Crate:     unic-ucd-version
Version:   0.9.0
Warning:   unmaintained
Title:     `unic-ucd-version` is unmaintained
Date:      2025-10-18
ID:        RUSTSEC-2025-0098
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0098

Crate:     yaml-rust
Version:   0.4.5
Warning:   unmaintained
Title:     yaml-rust is unmaintained.
Date:      2024-03-20
ID:        RUSTSEC-2024-0320
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0320

Crate:     anyhow
Version:   1.0.57
Warning:   unsound
Title:     Unsoundness in `Error::downcast_mut()`
Date:      2026-06-25
ID:        RUSTSEC-2026-0190
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0190

Crate:     atty
Version:   0.2.14
Warning:   unsound
Title:     Potential unaligned read
Date:      2021-07-04
ID:        RUSTSEC-2021-0145
URL:       https://rustsec.org/advisories/RUSTSEC-2021-0145

Crate:     bumpalo
Version:   3.9.1
Warning:   unsound
Title:     Use-after-free due to a lifetime error in `Vec::into_iter()`
Date:      2022-01-14
ID:        RUSTSEC-2022-0078
URL:       https://rustsec.org/advisories/RUSTSEC-2022-0078

Crate:     git2
Version:   0.14.2
Warning:   unsound
Title:     Potential undefined behavior when dereferencing Buf struct
Date:      2026-02-02
ID:        RUSTSEC-2026-0008
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0008

Crate:     git2
Version:   0.14.2
Warning:   unsound
Title:     Potential undefined behavior when calling Remote::list()
Date:      2026-05-12
ID:        RUSTSEC-2026-0183
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0183

Crate:     git2
Version:   0.14.2
Warning:   unsound
Title:     Potential undefined behavior with Signature from a buffer-created BlameHunk
Date:      2026-05-13
ID:        RUSTSEC-2026-0184
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0184

Crate:     memmap2
Version:   0.3.1
Warning:   unsound
Title:     Unchecked pointer offset in crate `memmap2`
Date:      2026-06-20
ID:        RUSTSEC-2026-0186
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0186

Crate:     openssl
Version:   0.10.40
Warning:   unsound
Title:     `openssl` `X509StoreRef::objects` is unsound
Date:      2023-11-23
ID:        RUSTSEC-2023-0072
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0072

Crate:     rand
Version:   0.7.3
Warning:   unsound
Title:     Rand is unsound with a custom logger using `rand::rng()`
Date:      2026-04-09
ID:        RUSTSEC-2026-0097
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0097

Crate:     rand
Version:   0.8.5
Warning:   unsound
Title:     Rand is unsound with a custom logger using `rand::rng()`
Date:      2026-04-09
ID:        RUSTSEC-2026-0097
URL:       https://rustsec.org/advisories/RUSTSEC-2026-0097

Crate:     tokio
Version:   1.18.2
Warning:   unsound
Title:     `tokio::io::ReadHalf<T>::unsplit` is Unsound
Date:      2023-01-11
ID:        RUSTSEC-2023-0005
URL:       https://rustsec.org/advisories/RUSTSEC-2023-0005

Crate:     tokio
Version:   1.18.2
Warning:   unsound
Title:     Broadcast channel calls clone in parallel, but does not require `Sync`
Date:      2025-04-07
ID:        RUSTSEC-2025-0023
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0023

