Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-7MCQ-F592-PF7VHighslice-deque: Slice Ring Buffer and Slice Deque contains four unique double-free vulnerabilities triggered through safe APIsGHSA-XRRQ-RRGQ-H89WLowstatic-alloc: static-alloc vulnerability leads to uninitialized read after allocating MemBumpCVE-2025-53549Mediummatrix-sdk: Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementationCVE-2025-53604Mediumweb-push: Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length headerCVE-2025-53359Mediumethereum: ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactionsCVE-2025-52884Lowrisc0-ethereum-contracts: RISC Zero Ethereum invalid commitment with digest value of zero accepted by Steel.validateCommitmentCVE-2025-52570Mediumletmeind: letmein connection limiter allows an arbitrary amount of simultaneous connectionsCVE-2025-52926Lowspytrap-adb: spytrap-adb Omission of Security-relevant InformationCVE-2025-52484Lowrisc0-zkvm: zkVM Underconstrained VulnerabilityCVE-2025-4366Highpingora-core: Pingora has a Request Smuggling VulnerabilityGHSA-9GHP-W2HM-VFPFMediumwasmtime-jit-debug: wasmtime_jit_debug Dumps Undefined Memory by `JitDumpFile`GHSA-V33J-V3X4-42QGMediumhurl: Regex literal in Hurl files are not escaped when exported to HTML, allowing injectionsCVE-2025-48937Mediummatrix-sdk-crypto: matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administratorCVE-2024-21486Mediumdeno: Deno vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2025-5791Highusers: users may append `root` to group listingsGHSA-PR59-JJR4-GCF6Lowanon-vec: anon-vec lacks sufficient checks in public APICVE-2025-48935Mediumdeno: Deno has --allow-read / --allow-write permission bypass in `node:sqlite`CVE-2025-48934Mediumdeno: Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesCVE-2025-48888Mediumdeno: Deno run with --allow-read and --deny-read flags results in allowedCVE-2025-24015Highdeno: Deno's AES GCM authentication tags are not verifiedGHSA-WV8J-M3HX-924JHigharrow2: Arrow2 allows out of bounds access in public safe APICVE-2025-48756Lowscsir: SCSIR has a Potential Unsound Issue in WriteSameCommandCVE-2025-48751Lowprocess_lock: process_lock has a Potential Unsound issue in unlockCVE-2025-48754Lowmemory_pages: memory_pages division by zeroCVE-2025-48752Lowprocess-sync: Process Sync has a Potential Unsound Issue in SharedMutex

Stop the waste.
Protect your environment with Kodem.