Debian Rust Security Tracker 🩺🦀

Open Advisories 13
Packages Needing Attention 32
Tracked Debian packages 205
Tracked advisories 688

Overall Package Status

Fully Patched (173) Affected (30) High Severity (2)

Open Advisories 13

Advisory Crate Patched Versions Debian Version Severity Packages Affected Patched:Affected Ratio
RUSTSEC-2026-0176 pyo3 >=0.29.0
0.28.2-1
6
RUSTSEC-2026-0154 russh >=0.60.3
0.57.1-2
high 1
RUSTSEC-2026-0153 russh-cryptovec >=0.60.3
0.59.0-1
high 1
RUSTSEC-2026-0119 hickory-proto >=0.26.1
0.25.2-3
6
RUSTSEC-2026-0118 hickory-proto 0.25.2-3
5
RUSTSEC-2026-0106 hickory-recursor 0.25.2-2
1
RUSTSEC-2026-0104 rustls-webpki >=0.103.13, <0.104.0-alpha.1
>=0.104.0-alpha.7
0.103.13+ds-1
0.101.7-7
8
RUSTSEC-2026-0099 rustls-webpki >=0.103.12, <0.104.0-alpha.1
>=0.104.0-alpha.6
0.103.13+ds-1
0.101.7-7
8
RUSTSEC-2026-0098 rustls-webpki >=0.103.12, <0.104.0-alpha.1
>=0.104.0-alpha.6
0.103.13+ds-1
0.101.7-7
8
RUSTSEC-2025-0140 gix-date >=0.12.0
0.15.3-1
2
RUSTSEC-2025-0044 slice-ring-buffer 0.3.4-4+b1
1
RUSTSEC-2023-0071 rsa 0.9.10-1+b1
medium 4
RUSTSEC-2023-0066 pleaser 0.5.6-2+b2
medium 2

Affected Packages 32

Package Version Advisories
cargo-c 0.10.16-2+b1 gix-date (RUSTSEC-2025-0140, CVE-2026-0810, GHSA-6mw6-mj76-grwc)
cargo-outdated 0.19.0-1+b1 gix-date (RUSTSEC-2025-0140, CVE-2026-0810, GHSA-6mw6-mj76-grwc)
gpg-sq 0.13.1-12 hickory-proto (RUSTSEC-2026-0119, GHSA-q2qq-hmj6-3wpp)
hickory-proto (RUSTSEC-2026-0118, GHSA-3v94-mw7p-v465)
gpgv-sq 0.13.1-12 hickory-proto (RUSTSEC-2026-0119, GHSA-q2qq-hmj6-3wpp)
hickory-proto (RUSTSEC-2026-0118, GHSA-3v94-mw7p-v465)
hickory-dns 0.25.2-3 hickory-proto (RUSTSEC-2026-0119, GHSA-q2qq-hmj6-3wpp)
hickory-proto (RUSTSEC-2026-0118, GHSA-3v94-mw7p-v465)
hypothesis-client 0.12.0-4+b2 rustls-webpki (RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8)
rustls-webpki (RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh)
rustls-webpki (RUSTSEC-2026-0098, GHSA-965h-392x-2mh5)
librust-hickory-proto-dev 0.25.2-3 hickory-proto (RUSTSEC-2026-0119, GHSA-q2qq-hmj6-3wpp)
hickory-proto (RUSTSEC-2026-0118, GHSA-3v94-mw7p-v465)
librust-hickory-recursor-dev 0.25.2-2 hickory-recursor (RUSTSEC-2026-0106)
librust-pleaser-dev 0.5.6-2+b2 pleaser (medium, RUSTSEC-2023-0066, CVE-2023-46277, GHSA-cgf8-h3fp-h956)
librust-pyo3-dev 0.28.2-1 pyo3 (RUSTSEC-2026-0176)
librust-rsa-dev 0.9.10-1+b1 rsa (medium, RUSTSEC-2023-0071, CVE-2023-49092, GHSA-c38w-74pg-36hr, GHSA-4grx-2x9w-596c)
librust-russh-cryptovec-dev 0.59.0-1 russh-cryptovec (high, RUSTSEC-2026-0153, CVE-2026-46673, GHSA-g9f8-wqj9-fjw5)
librust-russh-dev 0.57.1-2 russh (high, RUSTSEC-2026-0154, CVE-2026-46673, GHSA-g9f8-wqj9-fjw5)
librust-rustls-webpki-0.101-dev 0.101.7-7 rustls-webpki (RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8)
rustls-webpki (RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh)
rustls-webpki (RUSTSEC-2026-0098, GHSA-965h-392x-2mh5)
librust-slice-ring-buffer-dev 0.3.4-4+b1 slice-ring-buffer (RUSTSEC-2025-0044, GHSA-7mcq-f592-pf7v)
loggerhead 3.0.1+dfsg-2+b1 pyo3 (RUSTSEC-2026-0176)
nanopub 0.2.0+ds-1.1+b1 rsa (medium, RUSTSEC-2023-0071, CVE-2023-49092, GHSA-c38w-74pg-36hr, GHSA-4grx-2x9w-596c)
nethsm-pkcs11 2.0.0-2+b2 rustls-webpki (RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8)
rustls-webpki (RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh)
rustls-webpki (RUSTSEC-2026-0098, GHSA-965h-392x-2mh5)
numbat 1.11.0-5+b1 rustls-webpki (RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8)
rustls-webpki (RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh)
rustls-webpki (RUSTSEC-2026-0098, GHSA-965h-392x-2mh5)
ognibuild 0.2.14-1 pyo3 (RUSTSEC-2026-0176)
pleaser 0.5.6-2+b2 pleaser (medium, RUSTSEC-2023-0066, CVE-2023-46277, GHSA-cgf8-h3fp-h956)
prr 0.20.0-2+b2 rustls-webpki (RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8)
rustls-webpki (RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh)
rustls-webpki (RUSTSEC-2026-0098, GHSA-965h-392x-2mh5)
python3-pendulum 3.2.0-1+b1 pyo3 (RUSTSEC-2026-0176)
python3-pydantic-core 2.46.4-1 pyo3 (RUSTSEC-2026-0176)
python3-taskchampion-py 2.0.2-4+b1 pyo3 (RUSTSEC-2026-0176)
rbw 1.15.0-1 rsa (medium, RUSTSEC-2023-0071, CVE-2023-49092, GHSA-c38w-74pg-36hr, GHSA-4grx-2x9w-596c)
rpacket 0.1.4-1+b5 rsa (medium, RUSTSEC-2023-0071, CVE-2023-49092, GHSA-c38w-74pg-36hr, GHSA-4grx-2x9w-596c)
sequoia-git 0.6.0-1+b1 hickory-proto (RUSTSEC-2026-0119, GHSA-q2qq-hmj6-3wpp)
signal-tlsd 0.1.1-1 rustls-webpki (RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8)
rustls-webpki (RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh)
rustls-webpki (RUSTSEC-2026-0098, GHSA-965h-392x-2mh5)
sq 1.3.1-10 hickory-proto (RUSTSEC-2026-0119, GHSA-q2qq-hmj6-3wpp)
hickory-proto (RUSTSEC-2026-0118, GHSA-3v94-mw7p-v465)
tealdeer 1.8.1-1+b1 rustls-webpki (RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8)
rustls-webpki (RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh)
rustls-webpki (RUSTSEC-2026-0098, GHSA-965h-392x-2mh5)
wasm-bindgen 0.2.108+ds-2+b1 rustls-webpki (RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8)
rustls-webpki (RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh)
rustls-webpki (RUSTSEC-2026-0098, GHSA-965h-392x-2mh5)