Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-JM4V-58R5-66HJMediumsurrealdb: Uncaught Exception in surrealdbGHSA-8F24-6M29-WM2RMediumtracing: use-after-free in tracing GHSA-V363-RRF2-5FMJLowferris-says: ferris-says has undefined behavior when not using UTF-8CVE-2024-21670Mediumursa: CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credentialCVE-2024-22192Mediumursa: Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holdersCVE-2022-31021Lowanoncreds-clsignatures: Breaking unlinkability in Identity Mixer using malicious keysCVE-2024-21629Mediumevm: Rust EVM erroneousle handles `record_external_operation` error returnGHSA-P4V8-JGCV-9G75Highsafe_pqc_kyber: safe_pqc_kyber leaks parts of secret keysCVE-2023-50711Mediumvmm-sys-util: `serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory accessCVE-2023-53157Mediumrosenpass: Remotely exploitable denial of service in RosenpassGHSA-R24F-HG58-VFRWMediumunsafe-libyaml: unsafe-libyaml unaligned write of u64 on 32-bit and 16-bit platformsCVE-2023-48795Mediumrussh: Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka TerrapinGHSA-RJHF-4MH8-9XJQMediumzerocopy: Zerocopy: Some Ref methods are unsound with some type parametersGHSA-3MV5-343C-W2QGLowzerocopy: Ref methods into_ref, into_mut, into_slice, and into_slice_mut are unsound when used with cell::Ref or cell::RefMutGHSA-X5FR-7HHJ-34J3Highsurrealdb: Full Table Permissions by DefaultCVE-2023-6193Mediumquiche: Unbounded queuing of path validation messages in cloudflare-quicheCVE-2023-51661Highwasmer-cli: Wasmer filesystem sandbox not enforcedCVE-2023-6245Highcandid: Candid infinite decoding loop through specially crafted payloadCVE-2023-26154Mediumpubnub: pubnub Insufficient Entropy vulnerabilityCVE-2023-6180Mediumtokio-boring: tokio-boring vulnerable to resource exhaustion via memory leakGHSA-WJ7F-468M-6MV8Mediumbirdcage: Environment variables still accessible through /procCVE-2023-49092Mediumrsa: Marvin Attack: potential key recovery through timing sidechannelsGHSA-4GRX-2X9W-596CMediumrsa: Marvin Attack: potential key recovery through timing sidechannelsGHSA-XPHF-CX8H-7Q9GMediumopenssl: `openssl` `X509StoreRef::objects` is unsoundGHSA-48M6-WM5P-RR6HHighself_cell: Insufficient covariance check makes self_cell unsound

Stop the waste.
Protect your environment with Kodem.