VYPR

rpm package

opensuse/cargo-audit&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/cargo-audit&distro=openSUSE%20Tumbleweed

Vulnerabilities (12)

  • CVE-2026-82254HigAug 28, 2026
    affected < 0.22.2~git0.281452c-3.1fixed 0.22.2~git0.281452c-3.1

    gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills.

  • CVE-2026-82253HigAug 28, 2026
    affected < 0.22.2~git0.281452c-3.1fixed 0.22.2~git0.281452c-3.1

    gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to b

  • CVE-2026-82251HigAug 28, 2026
    affected < 0.22.2~git0.281452c-3.1fixed 0.22.2~git0.281452c-3.1

    gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and open() functions to repositories

  • CVE-2026-82250MedAug 28, 2026
    affected < 0.22.2~git0.281452c-3.1fixed 0.22.2~git0.281452c-3.1

    gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet to trigger an index out of bounds panic, a

  • CVE-2026-82247HigAug 28, 2026
    affected < 0.22.2~git0.281452c-3.1fixed 0.22.2~git0.281452c-3.1

    gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong

  • CVE-2026-25727MedFeb 6, 2026
    affected < 0.22.1~git0.efcde93-2.1fixed 0.22.1~git0.efcde93-2.1

    time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used

  • CVE-2026-25541HigFeb 4, 2026
    affected < 0.22.2~git0.281452c-2.1fixed 0.22.2~git0.281452c-2.1

    Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. Whe

  • CVE-2025-58160LowAug 29, 2025
    affected < 0.21.2~git0.18e58c2-2.1fixed 0.21.2~git0.18e58c2-2.1

    tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be i

  • CVE-2024-12224HigMay 30, 2025
    affected < 0.21.2~git0.18e58c2-2.1fixed 0.21.2~git0.18e58c2-2.1

    Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

  • CVE-2025-4574MedMay 13, 2025
    affected < 0.21.2~git0.18e58c2-2.1fixed 0.21.2~git0.18e58c2-2.1

    In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

  • CVE-2024-45405MedSep 6, 2024
    affected < 0.20.0~git66.972ac93-3.1fixed 0.20.0~git66.972ac93-3.1

    `gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolv

  • CVE-2022-24713HigMar 8, 2022
    affected < 0.16.0~git0.625c965-3.1fixed 0.16.0~git0.625c965-3.1

    regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane