{"schema_version":1,"title":"pyo3 (crates.io) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in pyo3 (crates.io): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures, was published on 12 June 2026.","url":"https://junglewise.ai/threats/technologies/pyo3","json_url":"https://junglewise.ai/threats/technologies/pyo3.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pyo3","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":8},"latest":[{"cvss":4,"slug":"pyo3-has-a-missing-sync-bound-on-pycfunction-new-closure-closures-14aaaa14","title":"PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures","severity":"medium","exploited":false,"published_at":"2026-06-12T20:09:05+00:00","url":"https://junglewise.ai/threats/pyo3-has-a-missing-sync-bound-on-pycfunction-new-closure-closures-14aaaa14"},{"cvss":6.3,"slug":"pyo3-missing-sync-bound-in-pycfunction-new-closure-37dd6bc7","title":"PyO3 missing Sync bound in PyCFunction new_closure","severity":"medium","exploited":false,"published_at":"2026-06-12T20:09:05+00:00","url":"https://junglewise.ai/threats/pyo3-missing-sync-bound-in-pycfunction-new-closure-37dd6bc7"},{"cvss":8.7,"slug":"pyo3-out-of-bounds-read-in-list-and-tuple-iterators-31441968","title":"PyO3 out-of-bounds read in list and tuple iterators","severity":"high","exploited":false,"published_at":"2026-06-12T19:32:47+00:00","url":"https://junglewise.ai/threats/pyo3-out-of-bounds-read-in-list-and-tuple-iterators-31441968"},{"cvss":4,"slug":"pyo3-has-an-out-of-bounds-read-in-nth-nth-back-for-pylist-and-pytuple-499de4a4","title":"PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators","severity":"medium","exploited":false,"published_at":"2026-06-12T19:32:47+00:00","url":"https://junglewise.ai/threats/pyo3-has-an-out-of-bounds-read-in-nth-nth-back-for-pylist-and-pytuple-499de4a4"},{"slug":"rustsec-2026-0176-out-of-bounds-read-in-nth-nth-back-for-pylist-and-f3042ce7","title":"RUSTSEC-2026-0176 - Out-of-bounds read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators","severity":"info","exploited":false,"published_at":"2026-06-11T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2026-0176-out-of-bounds-read-in-nth-nth-back-for-pylist-and-f3042ce7"},{"slug":"rustsec-2026-0177-missing-sync-bound-on-pycfunction-new-closure-e8081edc","title":"RUSTSEC-2026-0177 - Missing `Sync` bound on `PyCFunction::new_closure` closures","severity":"info","exploited":false,"published_at":"2026-06-11T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2026-0177-missing-sync-bound-on-pycfunction-new-closure-e8081edc"},{"cvss":4,"slug":"pyo3-has-type-confusion-when-accessing-data-from-sublasses-of-2db99dde","title":"PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature","severity":"medium","exploited":false,"published_at":"2026-02-19T20:25:46+00:00","url":"https://junglewise.ai/threats/pyo3-has-type-confusion-when-accessing-data-from-sublasses-of-2db99dde"},{"slug":"rustsec-2026-0013-type-confusion-when-accessing-data-from-sublasses-of-d320236a","title":"RUSTSEC-2026-0013 - Type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature targeting Python 3.12 and up","severity":"info","exploited":false,"published_at":"2026-02-18T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2026-0013-type-confusion-when-accessing-data-from-sublasses-of-d320236a"},{"cvss":4,"slug":"pyo3-risk-of-buffer-overflow-in-pystring-from-object-2cfae0bc","title":"PyO3 Risk of buffer overflow in `PyString::from_object`","severity":"medium","exploited":false,"published_at":"2025-04-02T13:19:19+00:00","url":"https://junglewise.ai/threats/pyo3-risk-of-buffer-overflow-in-pystring-from-object-2cfae0bc"},{"slug":"rustsec-2025-0020-risk-of-buffer-overflow-in-pystring-from-object-00351e9a","title":"RUSTSEC-2025-0020 - Risk of buffer overflow in `PyString::from_object`","severity":"info","exploited":false,"published_at":"2025-04-01T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2025-0020-risk-of-buffer-overflow-in-pystring-from-object-00351e9a"},{"slug":"build-corruption-when-using-pyo3-config-file-environment-variable-cb118867","title":"Build corruption when using `PYO3_CONFIG_FILE` environment variable","severity":"info","exploited":false,"published_at":"2024-12-05T19:06:20+00:00","url":"https://junglewise.ai/threats/build-corruption-when-using-pyo3-config-file-environment-variable-cb118867"},{"slug":"rustsec-2024-0409-build-corruption-when-using-pyo3-config-file-baa2bd6f","title":"RUSTSEC-2024-0409 - Build corruption when using `PYO3_CONFIG_FILE` environment variable","severity":"info","exploited":false,"published_at":"2024-12-04T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2024-0409-build-corruption-when-using-pyo3-config-file-baa2bd6f"},{"cvss":4,"slug":"duplicate-advisory-pyo3-has-a-risk-of-use-after-free-in-borrowed-reads-0a52725d","title":"Duplicate Advisory: PyO3 has a risk of use-after-free in `borrowed` reads from Python weak references","severity":"medium","exploited":false,"published_at":"2024-10-15T14:08:25+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-pyo3-has-a-risk-of-use-after-free-in-borrowed-reads-0a52725d"},{"cve":"CVE-2024-9979","cvss":3.1,"epss":0.0021,"slug":"cve-2024-9979-pyo3-has-a-risk-of-use-after-free-in-borrowed-reads-from-python","title":"RUSTSEC-2024-0378 - Risk of use-after-free in `borrowed` reads from Python weak references","severity":"low","exploited":false,"published_at":"2024-10-12T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-9979-pyo3-has-a-risk-of-use-after-free-in-borrowed-reads-from-python"},{"cve":"CVE-2020-35917","cvss":3.1,"epss":0.0039,"slug":"cve-2020-35917-reference-counting-error-in-pyo3","title":"RUSTSEC-2020-0074 - Reference counting error in `From<Py<T>>`","severity":"low","exploited":false,"published_at":"2020-11-28T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-35917-reference-counting-error-in-pyo3"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"surrealdb (crates.io)","slug":"surrealdb","vulnerabilities":118,"url":"https://junglewise.ai/threats/technologies/surrealdb"},{"name":"coreutils (crates.io)","slug":"crates-io-coreutils","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/crates-io-coreutils"},{"name":"wasmtime (crates.io)","slug":"wasmtime","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/wasmtime"},{"name":"deno (crates.io)","slug":"deno","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/deno"},{"name":"zebrad (crates.io)","slug":"zebrad","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/zebrad"},{"name":"openssl-src (crates.io)","slug":"openssl-src","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/openssl-src"},{"name":"openssl (crates.io)","slug":"crates-io-openssl","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/crates-io-openssl"},{"name":"rustfs (crates.io)","slug":"rustfs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/rustfs"},{"name":"ckb (crates.io)","slug":"ckb","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/ckb"},{"name":"diesel (crates.io)","slug":"diesel","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/diesel"},{"name":"russh (crates.io)","slug":"crates-io-russh","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/crates-io-russh"},{"name":"deepseek-tui (crates.io)","slug":"deepseek-tui","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/deepseek-tui"}],"technology":{"hub":true,"name":"pyo3 (crates.io)","slug":"pyo3","vendor":{"name":"crates.io","slug":"crates-io","url":"https://junglewise.ai/threats/vendors/crates-io"},"aliases":[],"homepage":"https://pyo3.rs/","repo_url":"https://github.com/PyO3/pyo3","description":"Rust bindings for the Python interpreter, allowing the creation of native Python extensions.","url":"https://junglewise.ai/threats/technologies/pyo3"},"most_severe":[{"cvss":8.7,"slug":"pyo3-out-of-bounds-read-in-list-and-tuple-iterators-31441968","title":"PyO3 out-of-bounds read in list and tuple iterators","severity":"high","exploited":false,"published_at":"2026-06-12T19:32:47+00:00","url":"https://junglewise.ai/threats/pyo3-out-of-bounds-read-in-list-and-tuple-iterators-31441968"},{"cvss":6.3,"slug":"pyo3-missing-sync-bound-in-pycfunction-new-closure-37dd6bc7","title":"PyO3 missing Sync bound in PyCFunction new_closure","severity":"medium","exploited":false,"published_at":"2026-06-12T20:09:05+00:00","url":"https://junglewise.ai/threats/pyo3-missing-sync-bound-in-pycfunction-new-closure-37dd6bc7"},{"cvss":4,"slug":"pyo3-has-a-missing-sync-bound-on-pycfunction-new-closure-closures-14aaaa14","title":"PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures","severity":"medium","exploited":false,"published_at":"2026-06-12T20:09:05+00:00","url":"https://junglewise.ai/threats/pyo3-has-a-missing-sync-bound-on-pycfunction-new-closure-closures-14aaaa14"},{"cvss":4,"slug":"pyo3-has-an-out-of-bounds-read-in-nth-nth-back-for-pylist-and-pytuple-499de4a4","title":"PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators","severity":"medium","exploited":false,"published_at":"2026-06-12T19:32:47+00:00","url":"https://junglewise.ai/threats/pyo3-has-an-out-of-bounds-read-in-nth-nth-back-for-pylist-and-pytuple-499de4a4"},{"cvss":4,"slug":"pyo3-has-type-confusion-when-accessing-data-from-sublasses-of-2db99dde","title":"PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature","severity":"medium","exploited":false,"published_at":"2026-02-19T20:25:46+00:00","url":"https://junglewise.ai/threats/pyo3-has-type-confusion-when-accessing-data-from-sublasses-of-2db99dde"},{"cvss":4,"slug":"pyo3-risk-of-buffer-overflow-in-pystring-from-object-2cfae0bc","title":"PyO3 Risk of buffer overflow in `PyString::from_object`","severity":"medium","exploited":false,"published_at":"2025-04-02T13:19:19+00:00","url":"https://junglewise.ai/threats/pyo3-risk-of-buffer-overflow-in-pystring-from-object-2cfae0bc"},{"cvss":4,"slug":"duplicate-advisory-pyo3-has-a-risk-of-use-after-free-in-borrowed-reads-0a52725d","title":"Duplicate Advisory: PyO3 has a risk of use-after-free in `borrowed` reads from Python weak references","severity":"medium","exploited":false,"published_at":"2024-10-15T14:08:25+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-pyo3-has-a-risk-of-use-after-free-in-borrowed-reads-0a52725d"},{"cve":"CVE-2020-35917","cvss":3.1,"epss":0.0039,"slug":"cve-2020-35917-reference-counting-error-in-pyo3","title":"RUSTSEC-2020-0074 - Reference counting error in `From<Py<T>>`","severity":"low","exploited":false,"published_at":"2020-11-28T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-35917-reference-counting-error-in-pyo3"},{"cve":"CVE-2024-9979","cvss":3.1,"epss":0.0021,"slug":"cve-2024-9979-pyo3-has-a-risk-of-use-after-free-in-borrowed-reads-from-python","title":"RUSTSEC-2024-0378 - Risk of use-after-free in `borrowed` reads from Python weak references","severity":"low","exploited":false,"published_at":"2024-10-12T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-9979-pyo3-has-a-risk-of-use-after-free-in-borrowed-reads-from-python"},{"slug":"rustsec-2026-0176-out-of-bounds-read-in-nth-nth-back-for-pylist-and-f3042ce7","title":"RUSTSEC-2026-0176 - Out-of-bounds read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators","severity":"info","exploited":false,"published_at":"2026-06-11T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2026-0176-out-of-bounds-read-in-nth-nth-back-for-pylist-and-f3042ce7"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}