VYPR

rpm package

opensuse/sccache&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/sccache&distro=openSUSE%20Tumbleweed

Vulnerabilities (21)

  • CVE-2026-67182HigJul 28, 2026
    affected < 0.17.0~1-2.1fixed 0.17.0~1-2.1

    Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream connections without va

  • CVE-2026-67181MedJul 28, 2026
    affected < 0.17.0~1-2.1fixed 0.17.0~1-2.1

    Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encodi

  • CVE-2026-66754MedJul 28, 2026
    affected < 0.17.0~1-2.1fixed 0.17.0~1-2.1

    Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a con

  • CVE-2026-66746MedJul 28, 2026
    affected < 0.17.0~1-2.1fixed 0.17.0~1-2.1

    Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D) or line feed (0x0A) bytes into attacker-controlled input. Attackers can exploit percent-decoded quer

  • CVE-2026-45784HigJul 17, 2026
    affected < 0.16.0~0-3.1fixed 0.16.0~0-3.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad.

  • CVE-2026-44662MedMay 14, 2026
    affected < 0.16.0~0-3.1fixed 0.16.0~0-3.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_

  • CVE-2026-42327HigMay 14, 2026
    affected < 0.16.0~0-3.1fixed 0.16.0~0-3.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref wraps the raw bytes with str::from_utf8_unch

  • CVE-2026-41898MedApr 24, 2026
    affected < 0.16.0~0-3.1fixed 0.16.0~0-3.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use

  • CVE-2026-41681HigApr 24, 2026
    affected < 0.16.0~0-3.1fixed 0.16.0~0-3.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta

  • CVE-2026-41678HigApr 24, 2026
    affected < 0.16.0~0-3.1fixed 0.16.0~0-3.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8,

  • CVE-2026-41677CriApr 24, 2026
    affected < 0.16.0~0-3.1fixed 0.16.0~0-3.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can caus

  • CVE-2026-41676HigApr 24, 2026
    affected < 0.16.0~0-2.1fixed 0.16.0~0-2.1

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,

  • CVE-2026-25727MedFeb 6, 2026
    affected < 0.13.0~1-2.1fixed 0.13.0~1-2.1

    time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used

  • CVE-2026-25541HigFeb 4, 2026
    affected < 0.17.0~1-2.1fixed 0.17.0~1-2.1

    Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. Whe

  • CVE-2024-12224HigMay 30, 2025
    affected < 0.12.0~1-1.1fixed 0.12.0~1-1.1

    Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

  • CVE-2025-3416LowApr 8, 2025
    affected < 0.9.1~22-2.1fixed 0.9.1~22-2.1

    A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.

  • CVE-2024-32650HigApr 19, 2024
    affected < 0.8.0~3-1.1fixed 0.8.0~3-1.1

    Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete

  • CVE-2023-26964HigApr 11, 2023
    affected < 0.4.1~18-2.1fixed 0.4.1~18-2.1

    An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).

  • CVE-2022-31394HigFeb 21, 2023
    affected < 0.4.0pre.7~0-2.1fixed 0.4.0pre.7~0-2.1

    Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.

  • CVE-2022-24713HigMar 8, 2022
    affected < 0.2.15~git0.6b6d2f7-11.1fixed 0.2.15~git0.6b6d2f7-11.1

    regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane

Page 1 of 2