Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-475V-PQ2G-FP9GLows2n-quic: s2n-quic potential denial of service via crafted stream framesGHSA-J57R-4QW6-58R3Lowrusty-paseto: rusty_paseto vulnerable to private key extraction due to ed25519-dalek dependencyCVE-2023-46135Mediumstellar-strkey: stellar-strkey vulnerable to panic in SignedPayload::from_payloadCVE-2024-21530Mediumcocoon: Sequential calls of encryption API (`encrypt`, `wrap`, and `dump`) result in nonce reuseCVE-2023-46115Hightauri-cli: Tauri's Updater Private Keys Possibly Leaked via Vite Environment VariablesCVE-2023-46277Highpleaser: Pleaser privilege escalation vulnerabilityCVE-2023-45812Highapollo-router: Apollo Router vulnerable to Improper Check or Handling of Exceptional ConditionsCVE-2024-43806Mediumrustix: rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosionCVE-2023-53158Mediumgix-transport: gix-transport code execution vulnerabilityCVE-2023-42811Mediumaes-gcm: AEADs/aes-gcm: Plaintext exposed in decrypt_in_place_detached even on tag verification failureCVE-2023-42805Highquinn-proto: Denial of Service issue in quinn-protoCVE-2023-42444Highphonenumber: phonenumber panics on parsing crafted RFC3966 inputsCVE-2023-42447Highblurhash: blurhash panics on parsing crafted inputsCVE-2023-42454Criticalsqlpage: SQLpage vulnerable to public exposure of database credentialsCVE-2023-42456Lowsudo-rs: sudo-rs Session File Relative Path Traversal vulnerabilityCVE-2023-43669Hightungstenite: Tungstenite allows remote attackers to cause a denial of serviceCVE-2023-41880Lowwasmtime: Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64CVE-2023-39916Criticalroutinator: NLnet Labs’ Routinator vulnerable to path traversalCVE-2023-39914Highbcder: BER/CER/DER decoder panics on invalid inputCVE-2023-4863Highlibwebp-sys2: libwebp: OOB write in BuildHuffmanTableGHSA-36XM-35QQ-795WMediuminventory: Inventory exposes reference to non-Sync data to an arbitrary threadGHSA-JCR6-4FRQ-9GJJMediumusers: Users vulnerable to unaligned read of `*const *const c_char` pointerGHSA-GHC8-5CGM-5RPFMediuminventory: Inventory fails to prohibit standard library access prior to initialization of Rust standard library runtimeCVE-2023-41317Mediumapollo-router: Apollo Router Unnamed "Subscription" operation results in Denial-of-ServiceGHSA-C2HM-MJXV-89R4Lowlexical: Multiple soundness issues in lexical

Stop the waste.
Protect your environment with Kodem.