Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-FWFX-RRV8-CRPFMediumrustyscript: op_panic in the base runtime can force a panic in the runtime's containing threadGHSA-4MW5-2636-4535Mediumjs-sandbox: op_panic in the base runtime can force a panic in the runtime's containing threadGHSA-2RXC-GJRP-VJHXMediumanstream: Unsoundness in anstreamGHSA-WWQ9-3CPR-MM53Highhashbrown: Borsh serialization of HashMap is non-canonicalGHSA-F95P-4CV5-8W8XLowlinkme: linkme fails to ensure slice elements match the slice's declared typeGHSA-X3F4-45XF-RJM7Mediumruzstd: `ruzstd` uninit and out-of-bounds memory readsCVE-2024-32468Lowdeno_doc: deno_doc's HTML generator vulnerable to Cross-site ScriptingGHSA-QG5G-GV98-5FFHMediumrustls: rustls network-reachable panic in `Acceptor::accept`GHSA-M52V-24P8-654FMediumsurrealdb: SurrealDB has an Uncaught Exception Sorting Tables by Random OrderGHSA-JC55-246C-R88FMediumsurrealdb: SurrealDB has an Uncaught Exception Handling Nonexistent RoleGHSA-H4F5-H82V-5W4RMediumsurrealdb: SurrealDB has an Uncaught Exception in Function Generating Random TimeGHSA-JP37-5QHW-MFFWMediumsharks: Sharks has a Bias of Polynomial Coefficients in Secret SharingGHSA-J3PX-Q95C-9683Mediumzlib-rs: zlib-rs stack overflow during decompression with malicious inputGHSA-RP9H-RF7G-HWGRLows2n-tls: s2n-tls has undefined behavior at process exitGHSA-G23H-7VF9-XC25Mediummimalloc: Mimalloc Can Allocate Memory with Bad AlignmentGHSA-FPR5-JP2J-4Q2FLowpaillier-zk: paillier-zk has ambiguous challenge derivationGHSA-RM66-9GH4-4GP8Lowcggmp21: cggmp21 vulnerable to ambiguous challenge derivationGHSA-PQPW-89W5-82V5Mediumsimd-json-derive: `simd-json-derive` vulnerable to `MaybeUninit` misuseGHSA-7JJX-3QW9-J6H6Lowcggmp21-keygen: cggmp21-keygen has ambiguous challenge derivationGHSA-X8JH-XJ3X-GX3CLowfast-float: `fast-float` has multiple soundness issuesCVE-2024-27529Mediumgithub.com/shareup/wasm-interpreter-apple: wasm3 uncontrolled memory allocation vulnerabilityGHSA-8M24-3CFX-9FJWLowsp1-recursion-circuit: sp1 has insufficient observation of cumulative sumCVE-2024-51990Criticaljj-lib: jj vulnerable to path traversal via crafted Git repositoriesCVE-2024-51756Lowcap-std: cap-std doesn't fully sandbox all the Windows device filenamesCVE-2024-51745Lowwasmtime: Wasmtime doesn't fully sandbox all the Windows device filenames

Stop the waste.
Protect your environment with Kodem.