- Affected Component:
ringcrate v0.17.9 (transitive dependency throughreqwest) - Severity: Low (AES functions may panic with overflow checking)
- Status: Monitoring for upstream fix
- Mitigation: Issue only affects AES operations with overflow checking enabled
- Recommendation: Update will be applied when
reqwestupdates its dependencies
The vulnerability is in a transitive dependency used for HTTPS/TLS operations. Normal CLI usage is not affected.
To check for security updates:
cargo auditLast updated: 2025-09-05