Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-64347Highapollo-router: Apollo Router Improperly Enforces Renamed Access Control DirectivesCVE-2025-62596Highyouki: youki container escape and denial of service due to arbitrary write gadgets and procfs write redirectsCVE-2025-62161Highyouki: youki container escape via "masked path" abuse due to mount race conditionsGHSA-7VJM-6QGQ-3MRQLowshaman: Shaman has soundness issues and is unmaintainedCVE-2025-62711Lowwasmtime: Wasmtime vulnerable to segfault when using component resourcesGHSA-WWXP-HXH6-8GF8Highbinary_vec_io: binary_vec_io access memory out-of-bounds in binary_read_to_ref and binary_write_from_refGHSA-X77X-7MMH-CXV3Mediumncurses: ncurses exposes uninitialized memory in string reading functionsGHSA-XCPM-76HF-C9CCLowborrowck_sacrifices: Borrowck Scarifices exposes uninitialized memory in any_as_u8_sliceGHSA-FP5X-7M4Q-449FLowdirect_ring_buffer: Direct Ring Buffer has uninitialized memory exposure in create_ring_bufferGHSA-H5J3-CRG5-8JQMLoworx-pinned-vec: orx-pinned-vec has undefined behavior in index_of_ptr with empty slicesCVE-2025-62518Highastral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header DesynchronizationCVE-2025-62370Highalloy-dyn-abi: alloy-dyn-abi has DoS vulnerability on `alloy_dyn_abi::TypedData` hashingGHSA-6FGX-X7M2-74QMLowtracexec: tracexec has `env` command argument injection via environment variables starting with dash in traced exec eventsCVE-2025-11695Highmongodb: MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection stringCVE-2025-62162Highcel: cel-rust May Panic During Parsing of Invalid CEL ExpressionsCVE-2025-61787Highdeno: Deno is Vulnerable to Command Injection on Windows During Batch File ExecutionCVE-2025-61786Lowdeno: Deno's --deny-read check does not prevent permission bypassGHSA-2PGJ-5CV2-6XXWHighfuel-vm: FuelVM is vulnerable to heap memory allocation re-use bugCVE-2025-61785Lowdeno: Deno's --deny-write check does not prevent permission bypassGHSA-466C-PFVV-V83GLowwrflib: wrflib has a soundness issue and is unmaintainedCVE-2025-61588Criticalrisc0-zkvm-platform: risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`GHSA-QR9H-X63W-VQFMMediumopenmls: OpenMLS improper persistence of the secret tree during message processingCVE-2025-59825Mediumastral-tokio-tar: astral-tokio-tar has a path traversal in tar extractionGHSA-MM7X-QFJJ-5G2CLowammonia: Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removalGHSA-393W-9X6H-8GC7Highpingora-core: Pingora update for MadeYouReset HTTP/2 vulnerability

Stop the waste.
Protect your environment with Kodem.