Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-RHFX-M35P-FF5JLowlru: `IterMut` violates Stacked Borrows by invalidating internal pointerCVE-2025-69255Mediumrustfs: RustFS gRPC GetMetrics deserialization panic enables remote DoSCVE-2025-68705Highrustfs: RustFS Path Traversal VulnerabilityCVE-2026-21895Lowrsa: rsa crate has potential panic on a prime being equal to 1CVE-2026-0810Mediumgix-date: gix-date can create non-utf8 string with `TimeBuf::as_str`CVE-2025-69257Hightheshit: theshit vulnerable to unsafe loading of user-owned Python rules when running as rootCVE-2025-68926Criticalrustfs: RustFS has a gRPC Hardcoded Token Authentication BypassGHSA-9FJQ-45QV-PCM7Mediumruint: ruint affected by unsoundness of safe `reciprocal_mg10`CVE-2025-67897Mediumsequoia-openpgp: Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too shortCVE-2025-65807Mediumsd: sd changes the group ownership of the source fileCVE-2025-67487Mediumstatic-web-server: Static Web Server vulnerable to a symbolic link path traversalCVE-2025-66627Highwasmi: Critical Use-After-Free in Wasmi's Linear MemoryCVE-2025-66622Lowmatrix-sdk-base: matrix-sdk-base denial of service via custom m.room.join_rules event valuesGHSA-XRV8-2PF5-F3Q7Mediumnitro-tpm-pcr-compute: nitro-tpm-pcr-compute may allow kernel command line modification by an account operatorGHSA-2CGV-28VR-RV6JHighlibcrux-intrinsics: libcrux incorrectly calculates on aarch64GHSA-MJ73-J457-8X9QLowmaxminddb: maxminddb's `Reader::open_mmap` unsoundly marks unsafe memmap operation as safeGHSA-PQ5V-RWP8-P7GMLowrtvm-interpreter: rtvm-interpreter lacks sufficient checks in public APIGHSA-2FJW-WHXM-9V4QCriticalnftnl: libnftnl has Heap-based Buffer Overflow in nftnl::Batch::with_page_size (nftnl-rs)CVE-2025-66017Highcggmp21: cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignaturesCVE-2025-66016Criticalcggmp21: cggmp21 has a missing check in the ZK proof used in CGGMP21CVE-2025-65947Highthread-amount: thread-amount Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOSCVE-2025-64517Mediumsudo-rs: sudo-rs doesn't record authenticating user properly in timestampCVE-2025-64345Lowwasmtime: Wasmtime provides unsound API access to a WebAssembly shared linear memoryCVE-2025-64170Lowsudo-rs: sudo-rs: Partial password reveal is possible after timeoutCVE-2025-64173Highapollo-router: Apollo Router Affected by an Access Control Bypass on Polymorphic Types

Stop the waste.
Protect your environment with Kodem.