# CVE Report
## 2026-06-30
| [RUSTSEC-2026-0007](https://rustsec.org/advisories/RUSTSEC-2026-0007) | vuln | `bytes` | bump to 1.12.0 (integer overflow in `BytesMut::reserve`) |
| [RUSTSEC-2026-0097](https://rustsec.org/advisories/RUSTSEC-2026-0097) | unsound | `rand` | bump to 0.8.6 (unsoundness with custom logger) |
| [RUSTSEC-2025-0134](https://rustsec.org/advisories/RUSTSEC-2025-0134) | unmaintained | `rustls-pemfile` | bump `reqwest` 0.11 → 0.12 to drop the unmaintained 1.x |