CVE-2026-77650

NameCVE-2026-77650
DescriptionThe append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-append-only-vec (PTS)trixie0.1.7-1fixed
forky, sid0.1.8-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-append-only-vecsource(unstable)(not affected)

Notes

- rust-append-only-vec <not-affected> (Only affects compromised and published 0.1.9 version)
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref
https://rustsec.org/advisories/RUSTSEC-2026-0262.html

Search for package or bug name: Reporting problems