Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-29787Highzip: zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File WriteCVE-2025-27512Lowzincati: Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methodsCVE-2025-30089Mediumgurk: gurk (aka gurk-rs) mishandles ANSI escape sequencesCVE-2025-27591Highbelow: Below has Incorrect Permission Assignment for Critical ResourceGHSA-FMWF-C46W-R8QMMediumqcp: qcp has possible crash/DOS in some build configurationsCVE-2025-53605Mediumprotobuf: Crash due to uncontrolled recursion in protobuf crateCVE-2025-4432Mediumring: Some AES functions may panic when overflow checking is enabled in ringCVE-2025-27498Mediumascon_aead: AEADs/ascon-aead: Plaintext exposed in decrypt_in_place_detached even on tag verification failureGHSA-V83Q-83HJ-RW38Mediumntpd: ntpd NTS client denial of service via wrongly sized cookiesGHSA-5PMW-9J92-3C4CHighopenh264-sys2: OpenH264 Rust API Openh264 Decoding Functions Heap Overflow VulnerabilityGHSA-F8QM-HMM3-FV7FCriticalnamada-apps: Namada-apps allows Excessive Computation in Mempool ValidationGHSA-82VG-5V4F-F9WQCriticalnamada-apps: Namada-apps can Crash with Excessive Computation in Mempool ValidationGHSA-2GW2-QGJG-XH6PCriticalnamada-apps: Namada-apps allows Post-Genesis Validator BypassGHSA-H7H7-6MX3-R89VLowfyrox-core: Fyrox has unsound usages of `Vec::from_raw_parts` GHSA-5V93-9MQW-P9MHHighorml-rewards: Uncaught Panic in ORML Rewards PalletGHSA-V7PC-74H8-XQ2HMediumhickory-proto: Hickory DNS failure to verify self-signed RRSIG for DNSKEYsCVE-2025-25194Mediumactivitypub_federation: Server-Side Request Forgery (SSRF) in activitypub_federationGHSA-QM2P-4W45-V2VRMediumgrcov: grcov has an out of bounds write triggered by crafted coverage dataCVE-2025-25188Mediumhickory-proto: Hickory DNS's DNSSEC validation may accept broken authentication chainsGHSA-MX2J-7CMV-353CMediumcosmwasm-vm: wasmvm: Malicious smart contract can slow down block productionCVE-2025-24898Mediumopenssl: rust-openssl ssl::select_next_proto use after freeCVE-2025-24802Highplonky2: Soundness issue with Plonky2 look up tablesGHSA-8655-XGH5-5VVQMediumfast-float: fast-fault has a segmentation fault due to lack of bound checkGHSA-JQCP-XC3V-F446Mediumfast-float2: fast-float2 has a segmentation fault due to lack of bound checkCVE-2025-24800Criticalismp-grandpa: ismp-grandpa crate accepted incorrect signatures

Stop the waste.
Protect your environment with Kodem.