← all corpora

rustsec-advisories

reference corpus · status live · domain SEC (Security advisories and identifiers) · lane A · refresh weekly · tags GLOBAL · ADVISORIES · VULNERABILITIES · SECURITY

What an agent uses it for

an agent reviewing Rust crate dependencies queries this for vulnerable crate versions, affected functions (271 RustSec advisories carry symbol lists), and patched releases: one text record per advisory from RustSec advisory-db (CC0) plus the crates.io OSV export (CC0, GHSA-sourced, zero alias overlap with RustSec)

Use it
xerj corpus add --from https://raw.githubusercontent.com/xerj-org/xerj/corpus-hub/tools/xerj-code/hub/rustsec-advisories.json
xerj corpus index rustsec-advisories then xerj code rustsec-advisories "your question"

Sources and pins

sourcepinlicencesizereview note
corpus-rust-vulns-txt 4bd96f2e2154CC0-1.0 3.8 MB / 1,963 files 1963 per-advisory text records: RustSec advisory-db @3461c0d8 (1228, CC0-1.0) + crates.io OSV export (735 GHSA-sourced, CC0-1.0) - verified ZERO alias overlap, genuinely disjoint. 271 records carry affected_functions symbol lists. G7 r1 5/5 (hard query: memoffset offset_of SIGILL). Supersedes the typed-JSON harvest that had no text field (#1158 class)

3.8 MB across 1,963 files. Added 2026-10-05.

Rights

CC0-1.0. Redistribution permitted with attribution per the licence review. The review block records a human opening each licence file at the pin. Detector output is a hint, never the verdict.

Retrieval spot-check (G7)

5.0/5 relevant. Graded .

Q: Our Cargo.toml pins the openssl crate at 0.8.x; was there a man-in-the-middle issue with its default certificate validation, and which release fixes it?
expect: corpus-rust-vulns-txt/rustsec-2016-0001.txt
top-5: corpus-rust-vulns-txt/rustsec-2016-0001.txt:1 / corpus-rust-vulns-txt/rustsec-2021-0056.txt:1 / rustsec/records.jsonl / rustsec/records.jsonl / corpus-rust-vulns-txt/rustsec-2026-0179.txt
grade: pass
Q: smallvec grow use after free double free which versions are affected and what do I patch to
expect: corpus-rust-vulns-txt/rustsec-2019-0009.txt
top-5: corpus-rust-vulns-txt/rustsec-2019-0009.txt / rustsec/records.jsonl / corpus-rust-vulns-txt/rustsec-2026-0029.txt:1 / corpus-rust-vulns-txt/rustsec-2026-0142.txt / corpus-rust-vulns-txt/rustsec-2026-0282.txt:1
grade: pass
Q: libpulse-binding Stream objects get_context get_format_info memory safety bug which functions are affected
expect: corpus-rust-vulns-txt/rustsec-2018-0021.txt
top-5: corpus-rust-vulns-txt/rustsec-2018-0021.txt / rustsec/records.jsonl / corpus-rust-vulns-txt/rustsec-2018-0020.txt:1 / corpus-rust-vulns-txt/rustsec-2019-0038.txt / rustsec/records.jsonl
grade: pass
Q: memoffset offset_of span_of unsoundness uninitialized memory dropped on panic
expect: corpus-rust-vulns-txt/rustsec-2019-0011.txt
top-5: corpus-rust-vulns-txt/rustsec-2019-0011.txt / rustsec/records.jsonl / corpus-rust-vulns-txt/rustsec-2023-0045.txt / corpus-rust-vulns-txt/rustsec-2020-0103.txt / corpus-rust-vulns-txt/rustsec-2026-0252.txt
grade: pass
Q: webauthn-rs-core origin validation flaw allowing subdomain suffixes like attacker's hermit-crab.example for crab.example
expect: corpus-rust-vulns-txt/ghsa-22w3-693w-x895.txt
top-5: corpus-rust-vulns-txt/ghsa-22w3-693w-x895.txt / osv/records.jsonl / corpus-rust-vulns-txt/ghsa-22w3-693w-x895.txt / corpus-rust-vulns-txt/ghsa-7gmj-67g7-phm9.txt / osv/records.jsonl
grade: pass