Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-68930Mediumrussh: Russh: Channel-scoped server callbacks can be reached without an open channelGHSA-3WHF-VGF2-9W6GMediumzaino-state: zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth LimitGHSA-6XX4-9WP6-65P7Mediumskilo: skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill sourceGHSA-HC4M-Q9JH-XW4JMediumnono-cli: nono-cli'scregistry pack verification can fail open when provenance metadata is absentCVE-2026-46428Criticallettre: lettre has TLS hostname verification disabled when using Boring TLS backendCVE-2026-16756Highaws-smithy-http-server: Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris…GHSA-2625-RW7M-5Q5XLowhubuum_client: Hubuum client library (Rust): Sensitive data may be exposed through default diagnosticsGHSA-QQC3-94QV-7FW3Mediumhubuum_client: Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network trafficGHSA-F45Q-W629-WR25Mediumhubuum_client: Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirectsGHSA-G9HV-X236-4QP3Mediumrussh: Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)GHSA-CQJC-RMPQ-XPRQMediumrussh: Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode recordsGHSA-5XVQ-CP9X-6P6RMediumrussh: Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)GHSA-4W2J-M93H-CJ5JHighquinn-proto: Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassemblyCVE-2026-53598Highprompty: Prompty: Arbitrary file read via file reference expansionCVE-2026-54542Lownimiq-primitives: nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proofCVE-2026-54541Lownimiq-primitives: nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keysGHSA-GGXF-9F6J-W742Mediumdiesel: Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`GHSA-7GCF-G7XR-8HXJMediumserde_with: serde_with: KeyValueMap serialization panics on empty sequence or map entriesCVE-2025-61670Lowwasmtime-c-api-impl: Wasmtime: Memory leak in C API with `externref` and `anyref` typesGHSA-99J7-FHR2-XFJ4Criticalexploration: `exploration` was removed from crates.io for malicious codeCVE-2026-54136Mediumwindmill-api: Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_searchCVE-2026-53956Mediumrattler_cache: Rattler vulnerable to package cache path traversal via conda package build stringGHSA-Q95X-7G78-RCCVMediumoneringbuf: OneRingBuf has a Use After Free VulnerabilityCVE-2026-53600Mediumasync-tar: async-tar PAX extension-header desync enables tar entry/content smugglingGHSA-CWV4-H3J5-W3CFLowrama: rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path

Stop the waste.
Protect your environment with Kodem.