GHSA-xwfj-jgwm-7wp5 · Severity: low · Ecosystem: rust — Tracing logging user input may result in poisoning logs with ANSI escape sequences
tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.
Conclusion & alert: CVE-2025-58160 is rated Low Risk (15.3/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-09-04 | 0.04% | 0.06% | +0.01% |
| 2 | 2025-08-30 | — | 0.04% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 2.3 | 4.0 | LOW |
|
— | — | [email protected] |
GHSA-xwfj-jgwm-7wp5 · Severity: low · Ecosystem: rust — Tracing logging user input may result in poisoning logs with ANSI escape sequences
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-58160 not yet assigned priority: Debian including 1 source packages (rust-tracing-subscriber), 4 status rows across 4 suites (bookworm, forky, sid, trixie): open 2, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2025-58160 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2025-58160 |
suse
|
low | CVE-2025-58160 severity low: SUSE including 319 source package names (2.2.1-5.100:libexpat1-2.7.1-slfo.1.1_5.1, 2.2.1-5.110:iputils-20221126-slfo.1.1_2.1, …), 698 product×package rows across 98 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Container suse/sl-micro/6.0/base-os-container, … (98 product lines)): Known Not Affected 239, Known Affected 231, Fixed 219, First Fixed 9. | https://www.suse.com/security/cve/CVE-2025-58160/ |
ubuntu
|
medium | CVE-2025-58160 medium priority: Ubuntu including 1 source packages (rust-tracing-subscriber), 5 status rows across 5 suites (jammy, noble, plucky, questing, upstream): needs-triage 3, DNE 1, ignored 1. | https://ubuntu.com/security/CVE-2025-58160 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||