Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Fedora has issued a security advisory for the uv package installer, a fast Python package installer written in Rust. The advisory addresses vulnerabilities affecting versions 0.9.5 and 43, which could impact users relying on pip and pip-tools workflows.
Multiple critical vulnerabilities have been identified in the Rust reqsign library, affecting services such as AWS, Azure, and Google. Key issues include a denial-of-service threat and a critical CVE-2025-62518 related to HTTP request signing and file reading implementations. Various patch releases...
Fedora 42 has released a security update addressing CVE-2025-62518, which affects the reqsign and rust-tikv-jemallocator libraries. The vulnerability involves a parser desynchronization issue when reading tar archives with mismatched size information in PAX/ustar headers. This fix is included in the...
Multiple security advisories were issued for the Fedora uv Python package installer, which is a fast alternative to pip. The updates address important security vulnerabilities, including CVE-2025, affecting users of Fedora 41, 42, and 43. These updates emphasize the need for users to apply patches t...