Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-3G92-F9CH-QJCMLowp3-symmetric: Plonky3: The sponge construction used to get a hash function from a cryptographic permutation is not collision resistant for inputs of…GHSA-XGP8-3HG3-C2MHLowrustls-webpki: webpki: Name constraints were accepted for certificates asserting a wildcard nameGHSA-965H-392X-2MH5Lowrustls-webpki: webpki: Name constraints for URI names were incorrectly acceptedCVE-2026-6654Highthin-vec: thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop PanicsGHSA-CQ8V-F236-94QCLowrand: Rand is unsound with a custom logger using rand::rng()CVE-2026-40323Highsp1_sdk: SP1 V6 Recursion Circuit Row-Count Binding GapCVE-2026-34069Mediumnimiq-consensus: nimiq-consensus panics via RequestMacroChain micro-block locatorCVE-2026-40093Criticalnimiq-blockchain: nimiq-blockchain is missing a wall-clock upper bound on block timestampsCVE-2026-35186Mediumwasmtime: Wasmtime has improperly masked return value from `table.grow` with Winch compiler backendCVE-2026-34987Criticalwasmtime: Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory accessCVE-2026-35195Mediumwasmtime: Wasmtime has out-of-bounds write or crash when transcoding component model stringsCVE-2026-34988Lowwasmtime: Wasmtime has data leakage between pooling allocator instancesCVE-2026-34983Lowwasmtime: Wasmtime has use-after-free bug after cloning `wasmtime::Linker`CVE-2026-34971Criticalwasmtime: Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 CraneliftCVE-2026-34946Mediumwasmtime: Wasmtime has host panic when Winch compiler executes `table.fill`CVE-2026-34945Lowwasmtime: Wasmtime has host data leakage with 64-bit tables and WinchCVE-2026-34944Mediumwasmtime: Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64 CVE-2026-34943Mediumwasmtime: Wasmtime has a possible panic when lifting `flags` component valueCVE-2026-34942Mediumwasmtime: Wasmtime: Panic when transcoding misaligned utf-16 stringsCVE-2026-34941Mediumwasmtime: Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcodingCVE-2026-39360Mediumrustfs: RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltrationCVE-2026-35533Highmise: Local settings bypass config trust checksCVE-2026-35406Highnetavark: netavark has incorrect error handling for malformed tcp packetsCVE-2026-35457Highlibp2p-rendezvous: libp2p-rendezvous: Unbounded rendezvous DISCOVER cookies enable remote memory exhaustionCVE-2026-35405Highlibp2p-rendezvous: libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers

Stop the waste.
Protect your environment with Kodem.