XERJ · corpus hub

← all corpora

rustsec-advisories

reference corpus · status live · category SEC (Security advisories & identifiers) · lane A · refresh weekly

What an agent uses it for

an agent reviewing Rust crate dependencies queries this for vulnerable crate versions, affected functions (271 RustSec advisories carry symbol lists), and patched releases — one text record per advisory from RustSec advisory-db (CC0) plus the crates.io OSV export (CC0, GHSA-sourced, zero alias overlap with RustSec)

Use it
xerj corpus add --from https://raw.githubusercontent.com/xerj-org/xerj/corpus-hub/tools/xerj-code/hub/rustsec-advisories.json
xerj corpus index rustsec-advisories → xerj code rustsec-advisories "your question"

Sources & pins

sourcepinlicencesizereview note
corpus-rust-vulns-txt 4bd96f2e2154…CC0-1.0 3.8 MB / 1,963 files 1963 per-advisory text records: RustSec advisory-db @3461c0d8 (1228, CC0-1.0) + crates.io OSV export (735 GHSA-sourced, CC0-1.0) - verified ZERO alias overlap, genuinely disjoint. 271 records carry affected_functions symbol lists. G7 r1 5/5 (hard query: memoffset offset_of SIGILL). Supersedes the typed-JSON harvest that had no text field (#1158 class)

3.8 MB across 1,963 files · added 2026-10-05

Rights

CC0-1.0 — redistribution permitted with attribution per the licence review . The review block records a human opening each licence file at the pin; detector output is a hint, never the verdict.

Retrieval spot-check (G7)

median 5.0/5 relevant —

Q: Our Cargo.toml pins the openssl crate at 0.8.x; was there a man-in-the-middle issue with its default certificate validation, and which release fixes it?
expect: corpus-rust-vulns-txt/rustsec-2016-0001.txt
top-5: corpus-rust-vulns-txt/rustsec-2016-0001.txt:1 · corpus-rust-vulns-txt/rustsec-2021-0056.txt:1 · rustsec/records.jsonl · rustsec/records.jsonl · corpus-rust-vulns-txt/rustsec-2026-0179.txt
grade: relevant
Q: smallvec grow use after free double free which versions are affected and what do I patch to
expect: corpus-rust-vulns-txt/rustsec-2019-0009.txt
top-5: corpus-rust-vulns-txt/rustsec-2019-0009.txt · rustsec/records.jsonl · corpus-rust-vulns-txt/rustsec-2026-0029.txt:1 · corpus-rust-vulns-txt/rustsec-2026-0142.txt · corpus-rust-vulns-txt/rustsec-2026-0282.txt:1
grade: relevant
Q: libpulse-binding Stream objects get_context get_format_info memory safety bug which functions are affected
expect: corpus-rust-vulns-txt/rustsec-2018-0021.txt
top-5: corpus-rust-vulns-txt/rustsec-2018-0021.txt · rustsec/records.jsonl · corpus-rust-vulns-txt/rustsec-2018-0020.txt:1 · corpus-rust-vulns-txt/rustsec-2019-0038.txt · rustsec/records.jsonl
grade: relevant
Q: memoffset offset_of span_of unsoundness uninitialized memory dropped on panic
expect: corpus-rust-vulns-txt/rustsec-2019-0011.txt
top-5: corpus-rust-vulns-txt/rustsec-2019-0011.txt · rustsec/records.jsonl · corpus-rust-vulns-txt/rustsec-2023-0045.txt · corpus-rust-vulns-txt/rustsec-2020-0103.txt · corpus-rust-vulns-txt/rustsec-2026-0252.txt
grade: relevant
Q: webauthn-rs-core origin validation flaw allowing subdomain suffixes like attacker's hermit-crab.example for crab.example
expect: corpus-rust-vulns-txt/ghsa-22w3-693w-x895.txt
top-5: corpus-rust-vulns-txt/ghsa-22w3-693w-x895.txt · osv/records.jsonl · corpus-rust-vulns-txt/ghsa-22w3-693w-x895.txt · corpus-rust-vulns-txt/ghsa-7gmj-67g7-phm9.txt · osv/records.jsonl
grade: relevant