Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-64684Mediumrmcp: RMCP: Custom HTTP headers leak to cross-origin redirect targetsCVE-2026-63128Highrmcp: RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-serviceCVE-2026-63127Highrmcp: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata DiscoveryCVE-2026-61544Highlibp2p-quic: libp2p-quic: Remote panic via certificate expiry race during QUIC handshakeGHSA-M3WP-48JR-VR4GHighmistralrs-server-core: mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoSGHSA-WFGQ-W7CQ-QJ7JHighmistralrs-server-core: mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_urlCVE-2025-24890Mediumgix-sec: gix-sec safe.directory protections absent for elevated administratorsCVE-2026-72925Medium@swc/html: SWC HTML minifier may allow script element breakout when minifying embedded JSONCVE-2026-63733Mediumsurrealdb-core: SurrealDB: Writes in a PERMISSIONS clause bypass table permissionsCVE-2026-63735Highsurrealdb: SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL pathCVE-2026-75911Highdeepseek-tui: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repositoryCVE-2026-75858Highdeepseek-tui: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)CVE-2026-75912Highdeepseek-tui: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without ApprovalCVE-2026-75856Criticaldeepseek-tui: CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinningCVE-2026-75915Highdeepseek-tui: CodeWhale: js_execution leaks parent environment to model context via missing env scrubCVE-2026-75913Highdeepseek-tui: CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without ApprovalCVE-2026-75857Highdeepseek-tui: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)CVE-2026-75859Highdeepseek-tui: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repositoryCVE-2026-75914Highdeepseek-tui: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytesCVE-2025-71390MediumSurrealDB: SurrealDB allows bypass of deny-net flags via DNS resolutionCVE-2026-63481Mediumhurl: Hurl: Cookies in Cookies section leak when redirecting to a different hostCVE-2026-55407Mediumbuffa: Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded AllocationCVE-2026-55406Mediumbuffa: Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in DerefCVE-2026-54788Highdatadog-opentelemetry: datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoSGHSA-2VH6-HW4J-32WWMediumgix-packetline: gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)

Stop the waste.
Protect your environment with Kodem.