Bugs Rust Won't Catch: Lessons from the uutils/coreutils CVE Audit
2026-04-29 · 469 words · 3 min read
A professional audit of the Rust reimplementation of GNU coreutils uncovered 44 CVEs — none caught by the borrow checker, Clippy, or cargo-audit. Here's what to watch for.