Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-43785Lowgitoxide-core: gitoxide-core does not neutralize special characters for terminalsGHSA-XMRP-424F-VFPXMediumsqlx: SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing CastsCVE-2024-44073Mediumminiscript: Miniscript allows stack consumptionGHSA-8327-84CJ-8XJMMediumalloy-json-abi: Stack overflow when parsing specially crafted JSON ABI stringsCVE-2024-43410Highrussh: Russh has an OOM Denial of Service due to allocation of untrusted amountCVE-2024-43367Highboa_engine: Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objectsGHSA-857Q-XMPH-P2V5Mediums2n-tls: s2n-tls's mTLS API ordering may skip client authenticationGHSA-RG2Q-2JH9-447QMediumcosmwasm-vm: Gas mispricing in cosmwasm-vmCVE-2024-41949Lowbiscuit-auth: biscuit-auth vulnerable to public key confusion in third party blockCVE-2024-41815Highstarship: Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commandsGHSA-66FW-43H8-F8P3Lowxmp_toolkit: XMP Toolkit's `XmpFile::close` can trigger undefined behaviorGHSA-CX7H-H87R-JPGRLowgix-attributes: The kstring integration in gix-attributes is unsoundCVE-2024-41178Mediumobject_store: Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log filesGHSA-Q445-7M23-QRMWMediumopenssl: openssl's `MemBio::get_buf` has undefined behavior with empty buffersCVE-2024-40648Mediummatrix-sdk-crypto: matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the checkCVE-2024-40644Highgix-path: gix-path can use a fake program files locationCVE-2024-40640Mediumvodozemac: vodozemac's usage of non-constant time base64 decoder could lead to leakage of secret key materialGHSA-5XGJ-PMJJ-GW49Lowrisc0-zkvm: RISC Zero zkVM notes on zero-knowledgeGHSA-GH9F-6XM2-C4J2Mediumsurrealdb: SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope UserCVE-2024-39697Criticalphonenumber: panic on parsing crafted phonenumber inputsGHSA-74R5-G7VC-J2V2Mediumzerovec-derive: zerovec-derive incorrectly uses `#[repr(packed)]`GHSA-XRV3-JMCP-374JMediumzerovec: zerovec incorrectly uses `#[repr(packed)]`CVE-2024-6382Mediummongodb: MongoDB Rust driver may issue unintended commandsCVE-2024-38528Highntpd: Unlimited number of NTS-KE connections can crash ntpd-rs serverCVE-2024-58261Lowsequoia-openpgp: Low severity (DoS) vulnerability in sequoia-openpgp

Stop the waste.
Protect your environment with Kodem.