Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-P2GM-FFR3-W2XWLowckb: Nervos CKB vulnerable to low-resource flood DDoS attacks through network messageGHSA-FJJ4-2Q73-JVGCLowckb: Nervos CKB calculation of program load cycles may be missed when executing in resume modeGHSA-4Q83-7CQ4-P6WGLowtokio: `tokio::io::ReadHalf<T>::unsplit` is UnsoundGHSA-8V4J-7JGF-5RG9Highwarp: Warp vulnerable to Path Traversal via Improper validation of Windows pathsGHSA-M4CH-RFV5-X5G3Mediumlibgit2-sys: git2-rs fails to verify SSH keys by defaultGHSA-G6PW-999W-J75MMediumelf_rs: ELF header parsing library doesn't check for valid offsetGHSA-F85W-WVC7-CRWCMediumbumpalo: bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`CVE-2023-22499Highdeno: Deno is vulnerable to race condition via interactive permission prompt spoofingCVE-2022-45299Criticalwebbrowser: webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URLCVE-2022-46176Mediumcargo: Cargo did not verify SSH host keysCVE-2023-22895Highbzip2: bzip2 allows attackers to cause a denial of service via a large file that triggers an integer overflowCVE-2023-22466Mediumtokio: Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipeGHSA-GFGM-CHR3-X6PXMediumprettytable-rs: prettytable-rs: Force cast a &Vec<T> to &[T] may lead to undefined behaviorGHSA-5WVV-Q5FV-2388Mediumhyper-staticfile: hyper-staticfile's location header incorporates user input, allowing open redirectCVE-2022-46171Mediumtauri: Tauri Filesystem Scope Glob Pattern is too PermissiveCVE-2022-23507Mediumtendermint-light-client-verifier: Tendermint light client verification not taking into account chain IDCVE-2022-3996Highopenssl-src: Denial of service by double-checked locking in openssl-srcCVE-2022-23523Lowlinux-loader: linux-loader reading beyond EOF could lead to infinite loopGHSA-9V25-R5Q2-2P6WMediummpl-candy-machine: Candy Machine Set Collection During Mint Missing CheckGHSA-8R76-FR72-J32WHighmpl-bubblegum: Creator Verification Error when Bubblegum ActivateGHSA-969W-Q74Q-9J8VMediumsecp256k1: Unsound API in `secp256k1` allows use-after-free and invalid deallocation from safe codeCVE-2022-23486Highlibp2p: libp2p DoS vulnerability from lack of resource managementGHSA-7P7C-PVVX-2VX3Mediumhyper-staticfile: hyper-staticfile's improper validation of Windows paths could lead to directory traversal attackCVE-2022-46149Mediumcapnp: Cap'n Proto and its Rust implementation vulnerable to out-of-bounds read due to logic error handling list-of-listCVE-2022-39397Mediumaliyun-oss-client: Leak in Aliyun KeySecret

Stop the waste.
Protect your environment with Kodem.