Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-22620Mediumgix-worktree-state: gix-worktree-state nonexclusive checkout sets executable files world-writableGHSA-C873-WFHP-WX5MHighsp1-stark: SP1 has missing verifier checks and fiat-shamir observationsCVE-2024-55226Lowvaultwarden: Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerabilityCVE-2024-55225Highvaultwarden: Vaultwarden vulnerable to user impersonationCVE-2024-55224Lowvaultwarden: Vaultwarden HTML injection vulnerabilityCVE-2024-52813Mediummatrix-sdk-crypto: matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identityCVE-2025-21620Highdeno_fetch: fetch: Authorization headers not dropped when redirecting cross-originGHSA-GMX7-GR5Q-85W5Lowmagic-crypt: magic-crypt uses insecure cryptographic algorithmsGHSA-GV7F-5QQH-VXFXLowxous: xous has unsound usages of `core::slice::from_raw_parts` GHSA-HQMP-G7PH-X543Mediumquincy: TunnelVision - decloaking VPNs using DHCPGHSA-WRW7-89JP-8Q8GMediumglib: Unsoundness in `Iterator` and `DoubleEndedIterator` impls for `glib::VariantStrIter`GHSA-H6XM-C6R4-VMWFMediumspl-token-swap: Unsound usages of `u8` type casting in spl-token-swapGHSA-F7QJ-V3VP-4856Mediumlibafl: libafl has unsound usages of `core::slice::from_raw_parts_mut` GHSA-3QX8-RV27-J6GPMediumkvm-ioctls: Undefined behaviour in `kvm_ioctls::ioctls::vm::VmFd::create_device`GHSA-4FG7-VXC8-QX5WMediumrage: rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary executionGHSA-2FF4-XFPR-M32RMediumhd-wallet: `Slip10Like` derivation method instantiated with certain curves may allow attacker to find derivation path which results into very long…GHSA-27VQ-HV74-7CQPLowsurrealdb: SurrealDB has Silent Failure to Overwrite Table Definition of Relation TypeGHSA-753P-WRJ5-G8FJHighpqcrypto-hqc: PQClean has a correctness error in HQC decapsulationGHSA-2Q97-M5RC-P3GPMediumgithub.com/CosmWasm/wasmvm/v2: CosmWasm VM Incorrect meteringGHSA-VMQH-5232-V43RMediumgithub.com/CosmWasm/wasmvm/v2: Panic in wasmvm can slow down block productionCVE-2024-12224Mediumidna: `idna` accepts Punycode labels that do not produce any non-ASCII when decodedGHSA-VXCF-C7MX-PG53Mediumpyo3: Build corruption when using `PYO3_CONFIG_FILE` environment variableGHSA-GW5W-5J7F-JMJJLowpprof: Unsound usages of `std::slice::from_raw_parts` CVE-2024-53857Highpgp: rPGP Potential Resource Exhaustion when handling Untrusted MessagesCVE-2024-53856Highpgp: rPGP Panics on Malformed Untrusted Input

Stop the waste.
Protect your environment with Kodem.