Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-J3W3-P6MR-3HRHMediumdyn-future: DynFuture Drop Can Construct a Dangling ReferenceGHSA-2C6H-4899-WJXRHighscaly: scaly: Multiple soundness issues in Rust safe APIsCVE-2026-34377Highzebrad: Zebra has a Consensus Failure due to Improper Verification of V5 TransactionsCVE-2026-34219Highlibp2p-gossipsub: libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handlingGHSA-FXC9-7J2W-VX54Criticalmpp: mpp has multiple payment bypass and griefing vulnerabilitiesCVE-2026-34202Criticalzebrad: Zebra node crash — V5 transaction hash panic (P2P reachable)GHSA-HFF2-GCPX-8F4PMediumapollo-router: Apollo Router Core: Browser Bug Enables Bypass of XS-Search Prevention via Read-Only Cross-Site Request ForgeryGHSA-CP57-FQ8G-QH6VHighlibcrux-ml-dsa: libcrux has an Incorrect Check of Signer Response Norm During VerificationGHSA-PV9V-5J35-XWCRHighlibcrux-poly1305: libcrux Panics During Standalone MAC OperationsGHSA-Q29P-9PFR-J652Highlibcrux-sha3: libcrux-sha3: Incorrect output from SHAKE squeeze functionsGHSA-434V-X5QV-PMH6Highlibcrux-ed25519: libcrux has All-Zero Key Generation Upon Catastrophic RNG FailureGHSA-XRF2-5R3P-5WGJHighlibcrux-ml-dsa: libcrux: Panic in Signature Hint Decoding During VerificationCVE-2026-33693Mediumactivitypub_federation: Activitypub-Federation has SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid()GHSA-PWJX-QHCG-RVJ4Mediumrustls-webpki: webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logicGHSA-9F94-5G5W-GF6RHighaws-lc-fips-sys: CRL Distribution Point Scope Check Logic Error in AWS-LCGHSA-394X-VWMW-CRM3Highaws-lc-sys: AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CNCVE-2026-33056Mediumtar: tar-rs `unpack_in` can chmod arbitrary directories by following symlinksCVE-2026-33055Mediumtar: tar-rs incorrectly ignores PAX size headers if header size is nonzeroCVE-2026-33241Highsalvo: Salvo Affected by Denial of Service via Unbounded Memory Allocation in Form Data ParsingCVE-2026-33242Highsalvo: Salvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway BypassCVE-2026-33040Highlibp2p-gossipsub: Gossipsub PRUNE.backoff Duration OverflowCVE-2026-32766Mediumastral-tokio-tar: astral-tokio-tar insufficiently validates PAX extensions during extractionCVE-2026-32829Highlz4_flex: lz4_flex's decompression can leak information from uninitialized memory or reused output bufferCVE-2026-32314Highyamux: Yamux vulnerable to remote Panic via malformed Data frame with SYN set and len = 262145CVE-2026-32260Highdeno: Deno vulnerable to command Injection via incomplete shell metacharacter blocklist in node:child_process

Stop the waste.
Protect your environment with Kodem.