Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-51502Mediumloona-hpack: loona-hpack Panic VulnerabilityGHSA-F77Q-R5QM-W4M8Mediumsp1-recursion-gnark-ffi: sp1-recursion-gnark-ffi has insufficient range checks of BabyBear arithmetic CVE-2024-9979Mediumpyo3: PyO3 has a risk of use-after-free in `borrowed` reads from Python weak referencesCVE-2024-47813Lowwasmtime: Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violationsCVE-2024-47763Mediumwasmtime: wasmtime has a runtime crash when combining tail calls with trapping importsGHSA-PFR9-2P92-QRHQMediumdbn: Databento Binary Encoding (DBN) has a heap buffer overflow using c_chars_to_str functionGHSA-9722-9J67-VJCRHighsurrealdb: Improper Authorization in Select PermissionsGHSA-QJRV-V6QP-X99XHighsurrealdb: SurrealDB has an Uncaught Exception Handling Parsing Errors on Empty StringsCVE-2024-47614Highasync-graphql: async-graphql Directive OverloadCVE-2024-47609Mediumtonic: Tonic has remotely exploitable denial of service vulnerabilityCVE-2024-46488Highsqlite-vec: Heap-based Buffer Overflow in sqlite-vecGHSA-2WQ5-G96F-MV3VMediumouch: Ouch! allows a segmentation fault due to use of uninitialized memoryGHSA-2326-PFPJ-VX3HLowlexical-core: lexical-core has multiple soundness issuesGHSA-64F8-PJGR-9WMRHighsurrealdb: Untrusted Query Object Evaluation in RPC APICVE-2024-45405Mediumgix-path: gix-path improperly resolves configuration path reported by GitCVE-2024-7884Highic_cdk: ic-cdk has a memory leak when calling a canister method via `ic_cdk::call`CVE-2024-8418Highaardvark-dns: Missing connection timeout in Aardvark-dnsGHSA-P2Q9-36VW-C468Higholm-sys: olm-sys: wrapped library unmaintained, potentially vulnerableCVE-2024-45311Highquinn-proto: Denial of service in quinn-proto when using `Endpoint::retry()`CVE-2024-45305Lowgix-path: gix-path uses local config across repos when it is the highest scopeCVE-2024-45389Mediumpagefind: DOM clobbering could escalate to Cross-site Scripting (XSS)GHSA-75QH-GG76-P2W4Mediumcosmwasm-vm: CWA-2023-004: Excessive number of function parameters in compiled WasmCVE-2024-43783Highapollo-router: Apollo Router Coprocessors may cause Denial-of-Service when handling request bodiesCVE-2024-43414Highapollo-router: Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queriesGHSA-WQ9X-QWCQ-MMGFHighdiesel: Diesel vulnerable to Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts

Stop the waste.
Protect your environment with Kodem.