Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-PP8R-VV2J-9J5VCriticaltraitobject: traitobject is UnmaintainedCVE-2022-36113Lowcargo: Cargo extracting malicious crates can corrupt arbitrary filesCVE-2022-36114Mediumcargo: Cargo extracting malicious crates can fill the file systemCVE-2022-3212Highaxum-core: axum-core has no default limit put on request bodiesCVE-2022-3029Highroutinator: NLnet Labs Routinator has Reachable Assertion vulnerabilityGHSA-C439-CHV8-8G2JHighos_socketaddr: `os_socketaddr` invalidly assumes the memory layout of std::net::SocketAddrGHSA-9Q5J-JM53-V7VRCriticallz4-sys: lz4-sys vulnerable to memory corruption via issue in liblz4GHSA-3FG9-HCQ5-VXRCMediumiana-time-zone: iana-time-zone vulnerable to use after free in MacOS / iOS implementationGHSA-JWH2-VRR9-VCP2Mediummz-avro: mz-avro's incorrect use of `set_len` allows for un-initialized memoryCVE-2022-25903Highopcua: opcua Vulnerable to Out-of-bounds WriteCVE-2022-25888Highopcua: Uncontrolled Resource Consumption in opcuaCVE-2022-36008Mediumfc-rpc: Incorrect parsing of EVM reversion exit reason in RPCGHSA-H864-M8VM-3XVJHighoqs: oqs's Post-Quantum Signature scheme Rainbow level I parametersets brokenGHSA-HRJV-PF36-JPMRMediumoqs: oqs's Post-Quantum Key Encapsulation Mechanism SIKE brokenGHSA-XPP3-XRFF-W6RHMediumrocksdb: rocksdb vulnerable to out-of-bounds readGHSA-2JQ9-6XX7-3H29Mediumtemporary: `temporary` makes use of uninitialized memoryGHSA-QRQQ-9C63-XFRGHightower-http: tower-http's improper validation of Windows paths could lead to directory traversal attackGHSA-9QXH-258V-666CMediumowning_ref: owning_ref vulnerable to multiple soundness issuesCVE-2022-35724Highapache-avro: Apache Avro Rust SDK vulnerable to reader looping in cycle endlessly, consuming CPUCVE-2022-36125Highapache-avro: Apache Avro Rust SDK corrupted data read can cause crashCVE-2022-36124Highapache-avro: Apache Avro Rust SDK's Reader could consume memory beyond allowed constraintsCVE-2022-35922Highwebsocket: Rust-WebSocket memory allocation based on untrusted lengthCVE-2022-35737Highlibsqlite3-sys: `libsqlite3-sys` via C SQLite improperly validates array indexCVE-2022-31173Highjuniper: Juniper is vulnerable to @DOS GraphQL Nested Fragments overflowGHSA-XQ3C-8GQM-V648Highasync-graphql: async-graphql / async-graphql - @DOS GraphQL Nested Fragments overflow

Stop the waste.
Protect your environment with Kodem.