Gfx-rs develops graphics abstraction and shader-compilation tools, principally naga and wgpu, that serve as bridges between application code and GPU rendering pipelines. These components sit in a specialized infrastructure layer where vulnerabilities tend to surface in memory-safety and type-handling contexts inherent to graphics translation and low-level GPU interaction; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gfx Rs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-36761CRITICAL naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs. | Jun 12, 2024 | 9.8 | 25 | NO | NO |
CVE-2018-13492HIGH The mintToken function of a smart contract implementation for naga, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitr | Jul 9, 2018 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gfx Rs.
Media articles that mention a CVE ID that affects a product developed by Gfx Rs — matched by CVE ID, not by vendor name.