Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-8H58-W33P-WQ3GHighpgp: rPGP affected by crash in message handling for deeply nested messagesGHSA-7587-4WV6-M68MHighpgp: rPGP vulnerable to parser crash on crafted RSA secret key packets through CVE-2026-21895GHSA-G433-PQ76-6CMFHighhpke-rs: Bug fixes in hpke-rs, hpke-rs-rust-cryptoGHSA-435G-FCV3-8J26Lowlibcrux-ecdh: Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`GHSA-XX7M-69FF-9CRPMediumsurrealdb: SurrealDB vulnerable to Denial of Service through scripting function memory edge caseGHSA-VGR2-R5HM-F6GFCriticalsha-rst: `sha-rst` was removed from crates.io for malicious codeGHSA-6V2J-VR4H-F632Criticalfinch_cli_rust: `finch_cli_rust` was removed from crates.io for malicious codeGHSA-XP79-9MXW-878JCriticalfinch-rst: `finch-rst` was removed from crates.io for malicious codeGHSA-X468-PHR8-H3P3Criticaluniswap-utils: `uniswap-utils` was removed from crates.io for malicious codeGHSA-3MMG-7C2Q-8938Criticalsha-rust: `sha-rust` was removed from crates.io for malicious codeGHSA-F8H5-X737-X4XRCriticalfinch-rust: `finch-rust` was removed from crates.io for malicious codeGHSA-382Q-FPQH-29F7Criticalpolymarket-clients-sdk: `polymarket-clients-sdk` was removed from crates.io for malicious codeGHSA-6662-54XR-8423Criticalevm-units: `evm-units` was removed from crates.io for malicious codeGHSA-GCQF-3G44-VC9PMediumactix-files: [actix-files] Panic triggered by empty Range header in GET request for static fileGHSA-8V2V-WJWG-VX6RMediumactix-files: actix-files has a possible exposure of information vulnerabilityCVE-2026-25628Highqdrant: qdrant has arbitrary file write via `/logger` endpointCVE-2026-25727Mediumtime: time vulnerable to stack exhaustion Denial of Service attackGHSA-J39J-6GW9-JW6HLowgit2: git2 has potential undefined behavior when dereferencing Buf struct GHSA-8X3W-QJ7J-GQHFHighopenmls: openmls has improper tag validationCVE-2026-25541Mediumbytes: bytes has integer overflow in BytesMut::reserveCVE-2026-25537Mediumjsonwebtoken: jsonwebtoken has Type Confusion that leads to potential authorization bypassCVE-2026-24762Mediumrustfs: RustFS Logs Sensitive Credentials in PlaintextCVE-2026-21862Highrustfs: RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headersGHSA-H37V-HP6W-2PP8Mediumml-dsa: ml-dsa's UseHint function has off by two error when r0 equals zeroCVE-2026-24889Mediumsoroban-sdk: soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64

Stop the waste.
Protect your environment with Kodem.