VDB
GCVE-110-OSM-2026-10790
GCVE-110-OSM-2026-10790
Advisory PublishedCVSS 8.8/10
This crates.io package was part of the coordinated software supply chain attack on the arrayref package. The maintainer droundy was compromised and several of their crates were compromised with new malicious dependencies. This crate is one of those new malicious dependencies.
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | aovine | all (affected) | — |
Browse GCVE Records
3,530 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.