Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-WR2M-38XH-RPC9Mediumlemmy_server: Lemmy user purging users or communities or banning users can delete images they didn't upload/exclusively useGHSA-RR8G-9FPQ-6WMGLowtokio: Tokio broadcast channel calls clone in parallel, but does not require `Sync`CVE-2025-31496Highapollo-compiler: Apollo Compiler Named Fragment Processing VulnerabilityCVE-2025-32380Highapollo-router: Apollo Router Query Validation Vulnerable to Excessive Resource Consumption via Named Fragment ProcessingCVE-2025-32033Highapollo-router: Apollo Router Operation Limits Vulnerable to Bypass via Integer OverflowCVE-2025-32034Highapollo-router: Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment ExpansionCVE-2025-32032Highapollo-router: Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Optimization BypassGHSA-794X-2RPG-RFGRMediumjj-lib: Jujutsu does not have SHA-1 collision detectionGHSA-4FCV-W3QC-PPGGMediumopenssl: rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`CVE-2025-31130Mediumgix-features: gitoxide does not detect SHA-1 collision attacksCVE-2025-31477Criticaltauri-plugin-shell: Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`GHSA-PPH8-GCV7-4QJ5Lowpyo3: PyO3 Risk of buffer overflow in `PyString::from_object`CVE-2024-13941Mediumouch: Ouch Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerabilityGHSA-67R5-RQWV-9P9QLowarray-init-cursor: array-init-cursor is unsound when used with types that implement `Drop`GHSA-J8X2-777P-23FCLowtough: tough cyclic delegation graphs are not detectedCVE-2025-2886Mediumtough: tough terminating targets role delegations are not respectedCVE-2025-2885Mediumtough: tough root metadata version is not checked for sequential versioningCVE-2025-2888Mediumtough: tough timestamp metadata is cached when it fails snapshot rollback checkCVE-2025-2887Mediumtough: tough failure to detect delegated target rollbackGHSA-9CC5-2PQ7-HFJ8Mediumxmas-elf: xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.GHSA-FC83-9JWQ-GC2MMediumweb-push: Web Push Denial of Service via malicious Web Push endpointGHSA-VGMH-MQM4-8J88Mediumpared: pared Vulnerable to Use After Free in `Parc` and `Prc` Due to Missing Lifetime ConstraintsCVE-2025-30160Highredlib: Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences FormCVE-2025-27612Mediumlibcontainer: Libcontainer is affected by capabilities elevation similar to GHSA-f3fp-gc8g-vw66CVE-2025-25500Mediumcosmwasm: CosmWasm Allows Bypass of Capability Restrictions in Blockchains

Stop the waste.
Protect your environment with Kodem.