Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-27803Highvaultwarden: Vaultwarden's Collection Management Operations Allowed Without `manage` Verification for Manager RoleCVE-2026-27802Highvaultwarden: Vaultwarden has Privilege Escalation via Bulk Permission Update to Unauthorized Collections by ManagerCVE-2026-27801Mediumvaultwarden: Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit EnforcementGHSA-HFPC-8R3F-GW53Highaws-lc-sys: AWS-LC has PKCS7_verify Signature Validation BypassGHSA-65P9-R9H6-22VJHighaws-lc-sys: AWS-LC has Timing Side-Channel in AES-CCM Tag VerificationGHSA-VW5V-4F2Q-W9XFHighaws-lc-sys: AWS-LC has PKCS7_verify Certificate Chain Validation BypassGHSA-5WHH-4Q9J-7V28Lowaws-kms-tls-auth: aws-kms-tls-auth vulnerable to memory overallocationGHSA-5PMP-JPCF-PWX6Criticaltracing-check: `tracing-check` was removed from crates.io for malicious codeCVE-2026-21882Hightheshit: theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-executionGHSA-J8CJ-HW74-64JVMediumhivex: Hive has Double-free and Use After Free VulnerabilitiesCVE-2025-13327Mediumuv: uv has ZIP payload obfuscation through parsing differentialsCVE-2026-27822Criticalrustfs: Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account TakeoverCVE-2026-27607Highrustfs: RustFS: Missing Post Policy Validation leads to Arbitrary Object WriteGHSA-X43W-PH7M-PFJXHighhexchat: hexchat crate has a Use After Free vulnerabilityCVE-2026-27572Mediumwasmtime: Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instanceCVE-2026-27204Mediumwasmtime: Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustionCVE-2026-27195Mediumwasmtime: Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` futureCVE-2026-27480Mediumstatic-web-server: Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernamesCVE-2026-27190Highdeno: Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_processGHSA-47QC-857F-7W7FHighpyo3: PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` featureGHSA-3288-P39F-RQPVLowkeccak: Unsoundness in opt-in ARMv8 assembly backend for `keccak`CVE-2026-26275Highhttpsig-hyper: Improper Digest Verification in httpsig-hyper May Allow Message Integrity BypassCVE-2026-26267Highsoroban-sdk-macros: The rs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collideGHSA-P5VF-5754-X7P3Criticalpolymarket-client-sdks: `polymarket-client-sdks` was removed from crates.io for malicious codeGHSA-C7PH-F7JM-XV4WMediumpgp: rPGP's integrity protection of encrypted data was not always checked

Stop the waste.
Protect your environment with Kodem.