Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-24850Mediumml-dsa: ML-DSA Signature Verification Accepts Signatures with Repeated Hint IndicesCVE-2026-24785Highclatter: Clatter has a PSK Validity Rule Violation issueCVE-2026-24783Highsoroban-fixed-point-math: soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with NegativesGHSA-5W5R-MF82-595PCriticalcapnp: Cap'n Proto has Undefined Behavior in constant::Reader and StructSchemaGHSA-RVR2-R3PV-5M4PHighoneshot: oneshot has potential Use After Free when used asynchronouslyCVE-2026-24116Mediumwasmtime: Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64CVE-2026-22696Criticaldcap-qvl: dcap-qvl has Missing Verification for QE IdentityCVE-2025-67124Mediumminiserve: miniserve affected by a TOCTOU and symlink race vulnerabilityGHSA-3V2X-9XCV-2V2VHighsurrealdb: SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and FunctionsGHSA-RJR4-V43M-PXQ6Lowtriton-vm: Triton VM has a Soundness Vulnerability due to Improper Sampling of RandomnessCVE-2026-22864Highdeno: Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypassCVE-2026-22863Criticaldeno: Deno node:crypto doesn't finalize cipherCVE-2026-22782Lowrustfs: RustFS's RPC signature verification logs shared secretCVE-2026-23519Highcmov: RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`CVE-2026-22705Mediumml-dsa: RustCrypto: Signatures has timing side-channel in ML-DSA decompositionCVE-2026-22700Highsm2: RustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKECVE-2025-15504Lowlief: LIEF is vulnerable to segmentation faultCVE-2026-22699Highsm2: SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()CVE-2026-22698Highsm2: SM2-PKE has 32-bit Biased Nonce VulnerabilityGHSA-585Q-CM62-757JLowmnl: mnl has segmentation fault and invalid memory read in `mnl::cb_run`GHSA-G59M-GF8J-GJF5Lowaws-sdk-accessanalyzer: AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter valueCVE-2026-22256Highsalvo: Salvo is vulnerable to reflected XSS in the list_html functionCVE-2026-22257Highsalvo: Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious namesCVE-2026-22043Mediumrustfs: RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account MintingCVE-2026-22042Mediumrustfs: RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation

Stop the waste.
Protect your environment with Kodem.