Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-CVMJ-47V9-35M9Highfuser: FUSE-Rust: Uninitalized memory read and leak caused by fuser crateGHSA-HHW4-XG65-FP2XMediumserde_yml: serde_yml crate is unsound and unmaintainedGHSA-GFXP-F68G-8X78Highlibyml: LibYML: `libyml::string::yaml_string_extend` is unsound and unmaintainedGHSA-95HM-PR6Q-298WHighfast-able: fast-able is vulnerable to DoS attack through insecure methodCVE-2025-59058Mediumhttpsig: httpsig-rs: HMAC verification is vulnerable to timing attackCVE-2025-11060MediumSurrealDB: SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query SubscriptionsCVE-2025-59047Lowmatrix-sdk-base: matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` methodGHSA-PFP7-VXGR-83PWHightoodee: toodee is vulnerable to Heap Buffer Overflow through its DrainCol DestructorCVE-2025-58359Mediumfrost-core: frost-core: refresh shares with smaller min_signers will reduce security of groupGHSA-XQJR-WFX3-GMXVMediumarray-queue: ArrayQueue's push_front is not panic-safeGHSA-3632-54Q8-M96XHigharenavec: arenavec has multiple memory corruption vulnerabilities in safe APIsCVE-2025-58160Lowtracing-subscriber: Tracing logging user input may result in poisoning logs with ANSI escape sequencesGHSA-9Q78-27F3-2JMHMediumwebp: webp crate may expose memory contents when encoding an imageCVE-2025-58066Mediumntpd-rs: DoS Vulnerability in ntpd-rsGHSA-655H-HG88-5QMFLowxcb: Rust XCB `xcb::Connection::connect_to_fd*` functions violate I/O safetyGHSA-QQ4C-HM99-979MMediumid-map: IdMap from_iter may lead to uninitialized memory being freed on dropGHSA-77H3-W9RX-HJ3QMediumscratchpad: User-defined implementations of the safe trait scratchpad::Tracking can cause heap buffer overflowsCVE-2025-54867Highyouki: Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.CVE-2025-55159Mediumslab: slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds checkCVE-2025-7054Highquiche: quiche connection ID retirement can trigger an infinite loopCVE-2025-54873Lowrisc0-zkvm: RISC Zero Underconstrained Vulnerability: DivisionCVE-2025-54804Mediumrussh: russh is missing overflow checks during channel windows adjustCVE-2025-54581Highvproxy: vproxy Divide by Zero DoS VulnerabilityCVE-2025-8283Lownetavark: Netavark Has Possible DNS Resolve Confusion CVE-2025-53901Lowwasmtime-wasi: Wasmtime CLI is vulnerable to host panic through its fd_renumber function

Stop the waste.
Protect your environment with Kodem.