Skip to content

security: 16 CVE advisories in Cargo.lock (bridge triage, Track E) #16

Description

@hyperpolymath

panic-attack estate sweep — Track E bridge triage

panic-attack bridge triage (RustSec advisory DB, with reachability analysis) found 16 CVE/advisory findings in this repo's Cargo.lock (out of 315 total dependencies; 16 vulnerable).

Severity: medium: 16
Reachability: phantom: 16
Classification: informational: 16

Each finding includes a recommended action (often Remove unused dependency for phantom-imported crates). Reachability phantom = declared in Cargo.toml but never imported in any .rs file — removing the dep eliminates the CVE entirely with no behavioural change.

Estate tracker: hyperpolymath/panic-attack#32.

Findings

full advisory list
GHSA-f26g-jm89-4g65  gix@0.79.0  medium  reach=phantom  class=informational  fix=
GHSA-fr8x-3vfx-f45h  gix@0.79.0  medium  reach=phantom  class=informational  fix=
GHSA-p3hw-mv63-rf9w  gix@0.79.0  medium  reach=phantom  class=informational  fix=
GHSA-pg4w-g64p-qwhj  gix@0.79.0  medium  reach=phantom  class=informational  fix=
GHSA-f89h-2fjh-2r9q  gix-fs@0.19.1  medium  reach=phantom  class=informational  fix=
GHSA-x494-mj8g-cj27  gix-pack@0.66.0  medium  reach=phantom  class=informational  fix=
GHSA-9857-6mw7-fq2m  gix-transport@0.54.0  medium  reach=phantom  class=informational  fix=
GHSA-p3hw-mv63-rf9w  gix-validate@0.11.0  medium  reach=phantom  class=informational  fix=
GHSA-cq8v-f236-94qc  rand@0.9.2  medium  reach=phantom  class=informational  fix=
RUSTSEC-2026-0097  rand@0.9.2  medium  reach=phantom  class=informational  fix=
GHSA-82j2-j2ch-gfr8  rustls-webpki@0.103.10  medium  reach=phantom  class=informational  fix=
GHSA-965h-392x-2mh5  rustls-webpki@0.103.10  medium  reach=phantom  class=informational  fix=
GHSA-xgp8-3hg3-c2mh  rustls-webpki@0.103.10  medium  reach=phantom  class=informational  fix=
RUSTSEC-2026-0098  rustls-webpki@0.103.10  medium  reach=phantom  class=informational  fix=
RUSTSEC-2026-0099  rustls-webpki@0.103.10  medium  reach=phantom  class=informational  fix=
RUSTSEC-2026-0104  rustls-webpki@0.103.10  medium  reach=phantom  class=informational  fix=

🤖 Discovered during the panic-attack estate sweep (2026-05-26) — Track E (bridge triage). See hyperpolymath/panic-attack#32 for campaign tracker.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions