Known vulnerabilities in rust-tokei
Vendor:
Fedoraproject
Software:
rust-tokei
Software CPE:
cpe:2.3:o:fedoraproject:rust-tokei:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
13
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
14.0.0-7.el9
14.0.0-7.fc43
14.0.0-7.fc44
14.0.0-7.el10_3
14.0.0-4.el9
14.0.0-4.el10_2
14.0.0-4.fc42
14.0.0-4.fc43
14.0.0-4.fc44
14.0.0-4.fc45
13.0.0~alpha.8-19.fc42
12.0.4-11.fc34
12.0.4-11.fc35
12.0.4-11.fc36
12.0.4-7.fc34
12.1.2-9.el9
12.1.2-9.fc39
12.1.2-9.fc40
12.1.2-9.fc41
12.1.2-8.fc38
12.1.2-8.fc39
12.1.2-8.fc40
12.1.2-8.fc41
Vulnerabilities (13)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU143594 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-5917 |
CWE-78 | High | 14.0.0-7.el9, 14.0.0-7.el10_3, 14.0.0-7.fc43, 14.0.0-7.fc44 | 16.08.2026 |
SB20260816530 SB2026081711 SB2026081712 and 7 more |
||
| #VU138491 - Improper Validation of Certificate with Host Mismatch CVE-2026-53583 |
CWE-297 | Medium | 14.0.0-7.el9, 14.0.0-7.el10_3, 14.0.0-7.fc43, 14.0.0-7.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 9 more |
||
| #VU138490 - Insufficiently Protected Credentials CVE-2026-53586 |
CWE-522 | Medium | 14.0.0-7.el9, 14.0.0-7.el10_3, 14.0.0-7.fc43, 14.0.0-7.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU138489 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-53584 |
CWE-22 | Low | 14.0.0-7.el9, 14.0.0-7.el10_3, 14.0.0-7.fc43, 14.0.0-7.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU138487 - Out-of-bounds read CVE-2026-53587 |
CWE-125 | Medium | 14.0.0-7.el9, 14.0.0-7.el10_3, 14.0.0-7.fc43, 14.0.0-7.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU138485 - Allocation of Resources Without Limits or Throttling CVE-2026-53585 |
CWE-770 | Medium | 14.0.0-7.el9, 14.0.0-7.el10_3, 14.0.0-7.fc43, 14.0.0-7.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU122823 - Type confusion CVE-2026-25537 |
CWE-843 | Medium | 14.0.0-4.el9, 14.0.0-4.el10_2, 14.0.0-4.fc42, 14.0.0-4.fc43, 14.0.0-4.fc44, 14.0.0-4.fc45 | 13.02.2026 |
SB2026021365 SB2026021366 SB2026021367 and 4 more |
||
| #VU101971 - Security Features CVE-2024-56201 |
CWE-254 | Low | 13.0.0~alpha.8-19.fc42 | 27.12.2024 |
SB2024122789 SB2025010203 SB2025010322 and 62 more |
||
| #VU96050 - Server-Side Request Forgery (SSRF) CVE-2024-39338 |
CWE-918 | Medium | 13.0.0~alpha.8-19.fc42 | 15.08.2024 |
SB2024081543 SB2024090326 SB2024090446 and 63 more |
||
| #VU86202 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-24575 |
CWE-835 | Medium | 12.1.2-8.fc38, 12.1.2-8.fc39, 12.1.2-8.fc40, 12.1.2-8.fc41 | 07.02.2024 |
SB2024020715 SB2024020801 SB2024020863 and 15 more |
||
| #VU86201 - Heap-based Buffer Overflow CVE-2024-24577 |
CWE-122 | High | 12.1.2-8.fc38, 12.1.2-8.fc39, 12.1.2-8.fc40, 12.1.2-8.fc41 | 07.02.2024 |
SB2024020715 SB2024020801 SB2024020863 and 29 more |
||
| #VU59898 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2022-21658 |
CWE-362 | High | 12.0.4-11.fc34, 12.0.4-11.fc35, 12.0.4-11.fc36 | 21.01.2022 |
SB2022012101 SB2022051149 SB2022031433 and 17 more |
||
| #VU55598 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2021-32810 |
CWE-362 | High | 12.0.4-7.fc34 | 05.08.2021 |
SB2021080510 SB2021100515 SB2021101208 and 34 more |