Skip to content

feat(security): Audit and remediate known CVEs / RustSec advisories in the dependency tree #3698

Description

@ryerraguntla

Description

Type: security
Labels: security, dependencies, C-tracking
Source: discussion #3678

Summary

An initial cargo audit scan of Cargo.lock (Jul 18, 2026) surfaced known
vulnerabilities, unmaintained crates, and one unsound/yanked crate across the
transitive dependency graph. This issue tracks triage and remediation of each
advisory: upgrade where a fix exists, replace/remove unmaintained crates where
feasible, and record an accepted-risk ignore entry (with justification) where no
fix is available.

Affected area / component

Connectors

Proposed solution

Motivation

CVE management is a baseline requirement for enterprise-grade software (see the
Log4j fallout referenced in #3678). Iggy ships production binaries and multiple
SDKs; unpatched advisories in the dependency graph are shipped to every operator.
Remediating now, plus wiring the automated gate in the sibling issues, prevents
regressions.

References: https://rustsec.org/, https://rustsec.org/advisories/,
https://github.com/advisories, https://osv.dev/

Advisories from initial scan

Vulnerabilities (fix available)

Crate Version Advisory Severity Fix
crossbeam-epoch 0.9.18 RUSTSEC-2026-0204 — invalid pointer deref in fmt::Pointer for Atomic/Shared - upgrade >=0.9.20
quick-xml 0.37.5 RUSTSEC-2026-0195 — unbounded namespace-declaration alloc (memory-exhaustion DoS) 7.5 high upgrade >=0.41.0
quick-xml 0.37.5 RUSTSEC-2026-0194 — quadratic run time on duplicate attribute-name check 7.5 high upgrade >=0.41.0
quick-xml 0.38.4 RUSTSEC-2026-0195 7.5 high upgrade >=0.41.0
quick-xml 0.38.4 RUSTSEC-2026-0194 7.5 high upgrade >=0.41.0
quick-xml 0.39.4 RUSTSEC-2026-0195 7.5 high upgrade >=0.41.0
quick-xml 0.39.4 RUSTSEC-2026-0194 7.5 high upgrade >=0.41.0

Multiple quick-xml versions present (0.37.5 / 0.38.4 / 0.39.4) indicate
duplicate versions pulled by different dependents. Consolidate to a single
>=0.41.0 where possible.

Vulnerabilities (no fix available — accept-risk with justification)

Crate Version Advisory Severity Note
rsa 0.9.10 RUSTSEC-2023-0071 — Marvin Attack, key recovery via timing sidechannel 5.9 medium no fixed upgrade available; document exposure + ignore entry

Unmaintained / unsound / yanked warnings

Crate Version Advisory Class
atomic-polyfill 1.0.3 RUSTSEC-2023-0089 unmaintained
bincode 1.3.3 RUSTSEC-2025-0141 unmaintained
paste 1.0.15 RUSTSEC-2024-0436 unmaintained
proc-macro-error 1.0.4 RUSTSEC-2024-0370 unmaintained
proc-macro-error2 2.0.1 RUSTSEC-2026-0173 unmaintained
rustls-pemfile 2.2.0 RUSTSEC-2025-0134 unmaintained
rustybuzz 0.20.1 RUSTSEC-2026-0206 unmaintained
ttf-parser 0.25.1 RUSTSEC-2026-0192 unmaintained
anyhow 1.0.102 RUSTSEC-2026-0190 — unsoundness in Error::downcast_mut() unsound
spin 0.9.8 (yanked) yanked

Scope / tasks

  • Reproduce the scan: cargo audit on current Cargo.lock, attach fresh output.
  • Upgrade crossbeam-epoch to >=0.9.20.
  • Consolidate + upgrade quick-xml to >=0.41.0; remove duplicate versions.
  • Upgrade anyhow past the unsound downcast_mut() (patched release).
  • Replace spin yanked pin with a valid release.
  • For each unmaintained crate: identify the dependent, upgrade the dependent to drop it, or record a justified accept.
  • For rsa (no fix): document exposure (is timing sidechannel reachable in Iggy's threat model?) and add an [advisories] ignore entry with a comment + review date.
  • Land any accepted-risk exceptions in deny.toml (coordinate with the cargo-deny gate issue).

Acceptance criteria

  • cargo audit passes, or every remaining finding has a documented, justified ignore entry with an owner and review date.
  • No duplicate quick-xml versions remain in Cargo.lock (or duplication is justified).
  • Fresh scan output attached to the issue showing before/after.

Related

  • Enable cargo deny in pre-merge checks (sibling issue).
  • Make production binaries auditable via cargo auditable (sibling issue).

Alternatives considered

No response

Contribution

  • I'm willing to submit a pull request to implement this feature

Good first issue

  • I think this could be a good first issue for a new contributor

Metadata

Metadata

Assignees

Labels

Type

No type

Fields

No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions