VYPR

apk package

chainguard/toda

pkg:apk/chainguard/toda

Vulnerabilities (3)

  • CVE-2025-58160LowAug 29, 2025
    affected < 0.2.4-r4fixed 0.2.4-r4

    tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be i

  • CVE-2025-5791HigJun 6, 2025
    affected < 0fixed 0

    A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

  • CVE-2020-26235MedNov 24, 2020
    affected < 0.2.4-r4fixed 0.2.4-r4

    In Rust time crate from version 0.2.7 and before version 0.2.23, unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires the user to set any environment variable in a different thread than the affected functions. T