Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-39393Highwasmtime: Wasmtime may have data leakage between instances in the pooling allocatorCVE-2022-39392Mediumwasmtime: Wasmtime out of bounds read/write with zero-memory-pages configurationGHSA-5M39-WX2Q-MXG3Mediumlzf: Invalid use of `mem::uninitialized` causes `use-of-uninitialized-value`CVE-2022-41874LowTauri: Tauri Filesystem Scope can be Partially BypassedGHSA-MCMR-49X3-4JQMHighckb: ckb type_id script resume may randomly failGHSA-7FW6-6MFJ-G3Q2Criticalckb: ckb: Transaction header_deps validation issue (network forking)GHSA-9MFC-CHWF-7WHFMediumckb: ckb: Large dep group requires a lot of resources to process but the cost to commit the transaction is very low.CVE-2022-3602Criticalopenssl-src: X.509 Email Address 4-byte Buffer OverflowCVE-2022-3786Highopenssl-src: X.509 Email Address Variable Length Buffer OverflowCVE-2022-39294Highconduit-hyper: conduit-hyper vulnerable to Denial of Service from unchecked request lengthCVE-2022-39354Mediumevm: Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)GHSA-FC4H-XCF3-QJ5FMediummatrix-sdk: matrix-sdk 0.6.0 logs access tokensCVE-2022-3358Highopenssl-src: Using a Custom Cipher with `NID_undef` may lead to NULL encryptionCVE-2022-39292Highslack-morphism: Exposure of sensitive Slack webhook URLs in debug logs and tracesCVE-2021-21235Mediumkamadak-exif: kamadak-exif vulnerable to Infinite loop when parsing PNG filesCVE-2022-39252Mediummatrix-sdk-crypto: matrix-sdk-crypto contains potential impersonation via room key forward responsesCVE-2022-39242Mediumpallet-ethereum: Weight not properly refunded after EVM executionGHSA-28R9-PQ4C-WP3CLowpersonnummer: personnummer/rust vulnerable to Improper Input ValidationCVE-2022-39974Highpywasm3: WASM3 Improper Input Validation vulnerabilityGHSA-P75V-367R-2V23Mediumcell-project: `cell-project` used incorrect variance when projecting through `&Cell<T>`GHSA-V8GQ-5GRQ-9728Highmozjpeg: mozjpeg DecompressScanlines::read_scanlines is UnsoundCVE-2022-39215Mediumtauri: Tauri's readDir Endpoint Scope can be Bypassed With Symbolic LinksCVE-2022-36086Highlinked_list_allocator: linked_list_allocator vulnerable to out-of-bound writes on `Heap` initialization and `Heap::extend`GHSA-RC23-XXGQ-X27GCriticalwee_alloc: wee_alloc is UnmaintainedGHSA-VFV3-9W6V-23JPCriticaltypemap: typemap is Unmaintained

Stop the waste.
Protect your environment with Kodem.