Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-6HCF-G6GR-HHCRHighopenssl: `openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereferenceCVE-2023-28448Mediumversionize: Versionize::deserialize implementation for FamStructWrapper<T> is lacking bound checks, potentially leading to out of bounds memory accessesGHSA-F5V5-CCQC-6W36Mediumasync-nats: async-nats vulnerable to TLS certificate common name validation bypassCVE-2023-28445CriticalDeno: Deno improperly handles resizable ArrayBufferGHSA-255R-3PRX-MF99Mediumrmp-serde: `rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8CVE-2023-28431Highpallet-evm-precompile-modexp: Frontier's modexp precompile is slow for even modulusGHSA-PPJR-267J-5P9XMediumstb_image: NULL pointer derefernce in `stb_image`CVE-2023-28113Mediumrussh: russh may use insecure Diffie-Hellman keysGHSA-P7MJ-XVXG-GRFFMediumout-reference: `out_reference::Out::from_raw` should be `unsafe`CVE-2023-26489Criticalwasmtime: wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64CVE-2023-27477Lowwasmtime: wasmtime vulnerable to miscompilation of `i8x16.select` with the same inputs on x86_64GHSA-WM8X-PHP5-HVQ6Mediummaligned: Maligned causes incorrect deallocationGHSA-5X36-7567-3CW6Mediumpartial_sort: partial_sort contains Out-of-bounds Read in release modeGHSA-MRRW-GRHQ-86GFMediumascii: Ascii (crate) allows out-of-bounds array indexing in safe codeGHSA-MC8H-8Q98-G5HRLowremove_dir_all: Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_allGHSA-XW5J-GV2G-MJM2Mediumcortex-m-rt: Miscompilation in cortex-m-rt 0.7.1 and 0.7.2GHSA-CF4G-FCF8-3CR9Mediumpnet_packet: `pnet_packet` buffer overrun in `set_payload` settersCVE-2022-4304Mediumopenssl-src: openssl-src subject to Timing Oracle in RSA DecryptionCVE-2023-0215Highopenssl-src: openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`CVE-2022-4203Criticalopenssl-src: openssl-src contains Read Buffer Overflow in X.509 Name ConstraintCVE-2023-0216Highopenssl-src: openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functionsCVE-2022-4450Highopenssl-src: openssl-src contains Double free after calling `PEM_read_bio_ex`CVE-2023-0217Highopenssl-src: openssl-src subject to NULL dereference validating DSA public keyCVE-2023-0401Highopenssl-src: openssl-src contains `NULL` dereference during PKCS7 data verificationCVE-2023-0286Highcryptography: Vulnerable OpenSSL included in cryptography wheels

Stop the waste.
Protect your environment with Kodem.