CVE-2026-77651

NameCVE-2026-77651
DescriptionThe arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-arrayref (PTS)bullseye0.3.5-1fixed
bookworm0.3.6-1fixed
trixie0.3.9-1fixed
forky, sid0.3.9-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-arrayrefsource(unstable)(not affected)

Notes

- rust-arrayref <not-affected> (Only affected compromised and published 0.3.10 version)
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
https://rustsec.org/advisories/RUSTSEC-2026-0260.html

Search for package or bug name: Reporting problems