Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53598Highprompty: Prompty: Arbitrary file read via file reference expansionCVE-2026-54542Lownimiq-primitives: nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proofCVE-2026-54541Lownimiq-primitives: nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keysGHSA-GGXF-9F6J-W742Mediumdiesel: Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`GHSA-7GCF-G7XR-8HXJMediumserde_with: serde_with: KeyValueMap serialization panics on empty sequence or map entriesCVE-2025-61670Lowwasmtime-c-api-impl: Wasmtime: Memory leak in C API with `externref` and `anyref` typesGHSA-99J7-FHR2-XFJ4Criticalexploration: `exploration` was removed from crates.io for malicious codeCVE-2026-54136Mediumwindmill-api: Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_searchCVE-2026-53956Mediumrattler_cache: Rattler vulnerable to package cache path traversal via conda package build stringGHSA-Q95X-7G78-RCCVMediumoneringbuf: OneRingBuf has a Use After Free VulnerabilityCVE-2026-53600Mediumasync-tar: async-tar PAX extension-header desync enables tar entry/content smugglingGHSA-CWV4-H3J5-W3CFLowrama: rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI pathCVE-2026-53531Mediumratex-parser: ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)CVE-2026-53530Highratex-parser: ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)GHSA-FQF6-GXHH-2XHWHighuucore: uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)CVE-2026-35381Lowuu_cut: cut: -s ignored in -z -d '' newline-delimiter modeCVE-2026-35361Lowuu_mknod: mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)CVE-2026-35341Highuu_mkfifo: mkfifo: permissions of an existing file are changed after FIFO creation failsCVE-2026-54496Criticalzebrad: Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action…CVE-2026-35366Mediumuu_printenv: printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)CVE-2026-35362Lowuucore: uucore: safe_traversal TOCTOU protection only enabled on LinuxCVE-2026-35365Mediumuu_mv: mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)CVE-2026-35358Mediumuu_cp: cp: -R reads device nodes as streams, destroying device semanticsCVE-2026-35363Mediumuu_rm: rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protectionCVE-2026-35347Mediumuu_comm: comm: FIFO/pipe inputs are drained before comparison (data loss / hang)

Stop the waste.
Protect your environment with Kodem.