Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52734Mediumzebrad: zebrad has unbounded memory leak in mempool download pipeline via timeout path cancel_handles retentionCVE-2026-52733Mediumzebra-state: zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tipCVE-2026-52739Mediumzebra-state: Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier RejectionCVE-2026-52738Mediumzebra-state: Zebra: Finalized address balance credit-first overflow on consensus-valid blocksCVE-2026-52737Mediumzebra-consensus: Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead blockCVE-2026-52735Criticalzebra-script: zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parserCVE-2026-52736Highzebra-state: Zebra has block suppression via NU5 same-header body poisoning of sent-hash cacheGHSA-H72H-PPCX-998PLowzebra-network: Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body lengthCVE-2026-52732Mediumzebrad: zebrad has mempool transaction admission denial via single-peer inbound queue saturationGHSA-C8W6-X74F-VMG3Mediumzebra-rpc: zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceiversGHSA-443G-GWGP-49X4Lowzebrad: zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector lengthCVE-2026-52731Mediumzebra-rpc: zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplateCVE-2026-50185Mediumcmov: Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set CVE-2026-49997Mediumsurrealdb: SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deletedGHSA-FWG2-GR34-Q3W8Mediumsurrealdb: SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitationGHSA-C8JX-96C9-8XRPMediumsurrealdb: SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast pathsGHSA-WP87-MGVQ-5J93Mediumsurrealdb: SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorizationGHSA-97VG-427P-8HX5Mediumsurrealdb: SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirectGHSA-6WQW-VHFR-9999Mediumsurrealdb: SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptionsGHSA-F82J-V89J-MF86Mediumsurrealdb: SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permissionGHSA-FPXG-5XMV-922MMediumsurrealdb: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`GHSA-6G9V-7GQ3-P2C6Mediumsurrealdb: SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messagesGHSA-4M82-P8CX-F94JMediumsurrealdb: SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controlsGHSA-65RJ-R9FH-JP2VMediumsurrealdb: SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket framesGHSA-GCWR-5MRF-FVCHMediumsurrealdb: SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

Stop the waste.
Protect your environment with Kodem.