Skip to content

security: 19 CVE advisories in Cargo.lock (bridge triage, Track E) #13

Description

@hyperpolymath

panic-attack estate sweep — Track E bridge triage

panic-attack bridge triage (RustSec advisory DB, with reachability analysis) found 19 CVE/advisory findings in this repo's Cargo.lock (out of 489 total dependencies; 19 vulnerable).

Severity: medium: 19
Reachability: phantom: 19
Classification: informational: 19

Each finding includes a recommended action (often Remove unused dependency for phantom-imported crates). Reachability phantom = declared in Cargo.toml but never imported in any .rs file — removing the dep eliminates the CVE entirely with no behavioural change.

Estate tracker: hyperpolymath/panic-attack#32.

Findings

full advisory list
RUSTSEC-2021-0139 ansi_term@0.12.1 medium reach=phantom class=informational fix=
RUSTSEC-2025-0141 bincode@1.3.3 medium reach=phantom class=informational fix=
RUSTSEC-2024-0384 instant@0.1.13 medium reach=phantom class=informational fix=
GHSA-8c75-8mhr-p7r9 openssl@0.10.77 medium reach=phantom class=informational fix=
GHSA-ghm9-cr32-g9qj openssl@0.10.77 medium reach=phantom class=informational fix=
GHSA-hppc-g8h3-xhp3 openssl@0.10.77 medium reach=phantom class=informational fix=
GHSA-phqj-4mhp-q6mq openssl@0.10.77 medium reach=phantom class=informational fix=
GHSA-pqf5-4pqq-29f5 openssl@0.10.77 medium reach=phantom class=informational fix=
GHSA-xmgf-hq76-4vx2 openssl@0.10.77 medium reach=phantom class=informational fix=
GHSA-xp3w-r5p5-63rr openssl@0.10.77 medium reach=phantom class=informational fix=
GHSA-xv59-967r-8726 openssl@0.10.77 medium reach=phantom class=informational fix=
GHSA-6xvm-j4wr-6v98 quinn-proto@0.11.9 medium reach=phantom class=informational fix=
RUSTSEC-2026-0037 quinn-proto@0.11.9 medium reach=phantom class=informational fix=
GHSA-cq8v-f236-94qc rand@0.8.5 medium reach=phantom class=informational fix=
RUSTSEC-2026-0097 rand@0.8.5 medium reach=phantom class=informational fix=
RUSTSEC-2025-0134 rustls-pemfile@2.2.0 medium reach=phantom class=informational fix=
GHSA-82j2-j2ch-gfr8 rustls-webpki@0.103.12 medium reach=phantom class=informational fix=
RUSTSEC-2026-0104 rustls-webpki@0.103.12 medium reach=phantom class=informational fix=
RUSTSEC-2024-0320 yaml-rust@0.4.5 medium reach=phantom class=informational fix=

🤖 Discovered during the panic-attack estate sweep (2026-05-26) — Track E (bridge triage). See hyperpolymath/panic-attack#32 for campaign tracker.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions