Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32322Mediumsoroban-sdk: rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reductionCVE-2026-31814Highyamux: Yamux vulnerable to remote Panic via malformed WindowUpdate creditCVE-2026-32129Highsoroban-poseidon: Poseidon V1 variable-length input collision via implicit zero-paddingGHSA-4CM8-XPFV-JV6FMediumzeptoclaw: ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist ValidationCVE-2026-32232Highzeptoclaw: ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlinkCVE-2026-32231Highzeptoclaw: ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload dataGHSA-725G-W329-G7QRMediumkora-lib: kora-lib: Token-2022 Transfer Fee Not Deducted During Payment VerificationGHSA-X442-M7CC-HR92Mediumkora-lib: kora-lib: Unrecognized Instruction Types Create Empty Stubs That Bypass Fee Payer PolicyGHSA-VHJ5-X93P-67JWMediumactix-web-lab: actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirectsCVE-2026-31812Highquinn-proto: Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsingCVE-2026-30960Criticalrssn: RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI InterfaceGHSA-PM4J-7R4Q-CCG8Lowsoroban-env-host: Soroban: Muxed address<->ScVal conversions may break after a conversion failureGHSA-MH23-RW7F-V5PQCriticaltime-sync: `time-sync` was removed from crates.io due to malicious codeCVE-2026-2836Highpingora-cache: Pingora vulnerable to cache poisoning via insecure-by-default cache keyCVE-2026-2835Criticalpingora-core: Pingora has HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding MisparsingCVE-2026-2833Criticalpingora-core: Pingora vulnerable to HTTP Request Smuggling via Premature UpgradeCVE-2026-29795Mediumstellar-xdr: stellar-xdr's StringM::from_str bypasses max length validationGHSA-XHW7-JHMP-J62JCriticaldnp3times: `dnp3times` was removed from crates.io due to malicious codeGHSA-5WP8-Q9MX-8JX8Criticalzeptoclaw: zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcardsGHSA-HHJV-JQ77-CMVXHighzeptoclaw: zeptoclaw has Android device shell blocklist bypass via argument permutationGHSA-WF45-3GPW-VRQVCriticaltime_calibrators: `time_calibrators` was removed from crates.io due to malicious codeCVE-2026-29178Highlemmy_routes: Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpointGHSA-77XJ-RRH3-WX3VCriticaltime_calibrator: `time_calibrator` was removed from crates.io due to malicious codeGHSA-6W86-WGWQ-RGQ8Mediumneqo-qpack: neqo-qpack has iInteger overflow in qpack dynamic table indexingCVE-2026-27898Mediumvaultwarden: Vaultwarden has Unauthorized Access via Partial Update API on Another User’s Cipher

Stop the waste.
Protect your environment with Kodem.