Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-W5W5-8VFH-XCJQHighwhoami: whoami stack buffer overflow on several Unix platformsGHSA-4V52-7Q2X-V4XJHigheyre: eyre: Parts of Report are dropped as the wrong type during downcastGHSA-W7HM-HMXV-PVHFHighhpack: HPACK decoder panics on invalid inputGHSA-Q6CP-QFWQ-4GCVMediumh2: h2 servers vulnerable to degradation of service with CONTINUATION FloodCVE-2024-27284Highcassandra-cpp: cassandra-rs's non-idiomatic use of iterators leads to use after freeCVE-2024-30266Lowwasmtime: Wasmtime vulnerable to panic when using a dropped extenref-typed element segmentCVE-2024-29640Highaliyundrive-webdav: aliyundrive-webdav vulnerable to Command InjectionCVE-2024-28854Hightls-listener: tls-listener affected by the slow loris vulnerability with default configurationCVE-2024-1765Mediumquiche: quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames floodingCVE-2024-1410Lowquiche: quiche vulnerable to unbounded storage of information related to connection ID retirementCVE-2024-28123Highwasmi: Wasmi Out-of-bounds Write for host to Wasm calls with more than 128 ParametersCVE-2024-28101Highapollo-router: Apollo Router's Compressed Payloads do not respect HTTP Payload LimitsCVE-2024-27934HighDeno: *const c_void / ExternalPointer unsoundness leading to use-after-freeCVE-2024-27933Highdeno: Deno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypassCVE-2024-27932Mediumdeno: Deno's improper suffix match testing for DENO_AUTH_TOKENSCVE-2024-27936Highdeno: Deno's deno_runtime vulnerable to interactive permission prompt spoofing via improper ANSI strippingCVE-2024-27935Highdeno: Deno's Node.js Compatibility Runtime has Cross-Session Data ContaminationCVE-2024-27931Mediumdeno: Insufficient permission checking in `Deno.makeTemp*` APIsCVE-2024-27308Highmio: Mio's tokens for named pipes may be delivered after deregistrationGHSA-Q3GG-M8HR-H4X4Highsurrealdb: Externally Controlled Format String in Scripting FunctionsGHSA-6WR5-JMPR-MJCXMediumsurrealdb: Uncaught Exception in Macro Expecting Native Function to ExistGHSA-8XFF-473H-F863Mediumsurrealdb: Uncaught Exception Handling Parsing Errors on Line TerminatorsCVE-2024-21491Mediumsvix: svix vulnerable to Authentication BypassGHSA-22Q8-GHMQ-63VFHighlibgit2-sys: libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2GHSA-X5J2-G63M-F8G4Highpqc_kyber: pqc_kyber KyberSlash: division timings depending on secrets

Stop the waste.
Protect your environment with Kodem.