View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Attackers Poisoned Three Rust Crates With Build-Time Malware

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Attackers Poisoned Three Rust Crates With Build-Time Malware โ€” blog.rust-lang.org

๐Ÿ”“ CVEs & KEV

  • CVE-2026-71485 โ€” CVSS 9.1 โ€” Centrifugo: Client-forgeable headers emulation lets any client spoof headers ...

  • CVE-2026-77638 โ€” CVSS 8.9 โ€” Tor Race Condition Allows Onion Service Impersonation

  • CVE-2026-74836 โ€” CVSS 8.7 โ€” HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandi...

  • CVE-2026-53804 โ€” CVSS 8.6 โ€” OTRS Community Edition OS Command Injection via PGP ConfigurationOTRS Communi...

  • CVE-2026-77148 โ€” CVSS 8.6 โ€” Critical Stack Buffer Overflow in Comfast CF-N1-S Web Management

  • CVE-2026-69242 โ€” CVSS 8.4 โ€” libvips: Integer overflow leading to heap buffer overflow leading to possible...

  • CVE-2026-77642 โ€” CVSS 7.5 โ€” tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consens...

  • CVE-2026-70651 โ€” CVSS 6.9 โ€” libvips: Possible integer overflow when reading multi-page TIFF images via Im...

  • CVE-2026-77641 โ€” CVSS 6.5 โ€” tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLU...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check