VYPR

rpm package

opensuse/sccache&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/sccache&distro=openSUSE%20Leap%2016.0

Vulnerabilities (19)

  • CVE-2026-93602MedSep 18, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers with a compromised trusted issuing

  • CVE-2026-93601LowSep 18, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was treat

  • CVE-2026-93600LowSep 18, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Because name constraints are restrictions on othe

  • CVE-2026-93599HigSep 18, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_

  • CVE-2026-67182HigJul 28, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream connections without va

  • CVE-2026-67181MedJul 28, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encodi

  • CVE-2026-66754MedJul 28, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a con

  • CVE-2026-66746MedJul 28, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D) or line feed (0x0A) bytes into attacker-controlled input. Attackers can exploit percent-decoded quer

  • CVE-2026-45784HigJul 17, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad.

  • CVE-2026-44662MedMay 14, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_

  • CVE-2026-42327HigMay 14, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref wraps the raw bytes with str::from_utf8_unch

  • CVE-2026-41898MedApr 24, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use

  • CVE-2026-41681HigApr 24, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta

  • CVE-2026-41678HigApr 24, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8,

  • CVE-2026-41677CriApr 24, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can caus

  • CVE-2026-41676HigApr 24, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,

  • CVE-2026-25727MedFeb 6, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used

  • CVE-2026-25541HigFeb 4, 2026
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. Whe

  • CVE-2024-12224HigMay 30, 2025
    affected < 0.18.0~2-160000.1.1fixed 0.18.0~2-160000.1.1

    Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.