Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-33290Lowgit-url-parse: git-url-parse crate vulnerable to Regular Expression Denial of ServiceGHSA-5FM9-H728-FWPJMediumtrust-dns-server: trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packetsCVE-2023-53161Lowbuffered-reader: buffered-reader vulnerable to out-of-bounds array access leading to panicCVE-2023-53160Lowsequoia-openpgp: sequoia-openpgp vulnerable to out-of-bounds array access leading to panicCVE-2023-34411Highxml-rs: xml-rs vulnerable to denial of service via invalid token in XML documentCVE-2023-33966Highdeno: Missing "--allow-net" permission check for built-in Node modulesCVE-2023-1521Highsccache: sccache vulnerable to privilege escalation if server is run as rootCVE-2023-33192Highntpd: Improper handling of NTS cookie length that could crash the ntpd-rs serverCVE-2023-27075Mediummicrobin: Stored cross site scripting in MicrobinCVE-2023-31134Mediumtauri: Tauri Open Redirect Vulnerability Possibly Exposes IPC to External SitesCVE-2023-30624Lowwasmtime: Undefined Behavior in Rust runtime functionsCVE-2023-30610Mediumaws-sigv4: AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sendingGHSA-QVC4-78GW-PV8PMediumenumflags2: Adverserial use of `make_bitflags!` macro can cause undefined behaviorGHSA-FJX5-QPF4-XJF2Mediumborsh: Parsing borsh messages with ZST which are not-copy/clone is unsoundCVE-2023-26964Mediumh2: h2 vulnerable to denial of serviceGHSA-FQ33-VMHV-48XHMediumntru: ntru-rs has unsound FFI: Wrong API usage causes write past allocated areaGHSA-2QV5-7MW5-J3CGMediumspin: spin-rs initialisation failure in `Once::try_call_once` can lead to undefined behaviour for other initialisersCVE-2023-26103Mediumdeno: Regular Expression Denial of Service in Deno.upgradeWebSocket APICVE-2023-28631Mediumcomrak: Comrak AST node data is not validated (GHSL-2023-049)GHSA-XXMQ-4VPH-956WMediumcomrak: Comrak vulnerable to production of excessive output when parsing Markdown (GHSL-2023-048)CVE-2023-28626Mediumcomrak: Comrak vulnerable to quadratic runtime issues when parsing Markdown (GHSL-2023-047)GHSA-WVC4-J7G5-4F79Mediumnats: NATS TLS certificate common name validation bypassCVE-2023-28446Highdeno_runtime: Interactive `run` permission prompt spoofing via improper ANSI neutralizationGHSA-3GXF-9R58-2GHGMediumopenssl: `openssl` `X509NameBuilder::build` returned object is not thread safeGHSA-9QWG-CRG9-M2VCHighopenssl: `openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read

Stop the waste.
Protect your environment with Kodem.