Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-4V76-CW68-4VC9Mediumsurrealdb: SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table requiredGHSA-6VG3-HGRW-P5GFMediumsurrealdb: SurrealDB has an Authorization Bypass via Composite Record-id PathsGHSA-VJJX-RFW4-RMFCMediumsurrealdb: SurrealDB: Graph traversal bypasses table SELECT permissionsGHSA-98FX-66CF-FC7CMediumsurrealdb: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth levelGHSA-Q8QP-67F9-WR3FMediumsurrealdb: SurrealDB vulnerable to Denial of Service due to nested types annotationsGHSA-WJJJ-24CX-F28GHighsurrealdb: SurrealDB has unauthenticated remote DoS via malformed RPC `use` callGHSA-Q729-696Q-G9PQHighsurrealdb: SurrealDB has Denial of Service in JSON parser due to nested objectsGHSA-4VGR-H27G-CF9PHighsurrealdb: SurrealDB: HTTP RPC Session Race Condition Allows Privilege EscalationGHSA-5QFP-32CF-69JHHighsurrealdb: SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callersCVE-2026-5223Mediumcargo: Cargo crates in third party registries can override the cached source of other cratesCVE-2026-5222Lowcargo: Cargo can be coerced to share credentials between registriesCVE-2026-48504Mediumopentelemetry_sdk: opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagationGHSA-FQ3W-P4FG-MW73Lowfixurjavainstall: fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`CVE-2026-55448Mediummise: Mise's local credential_command executes untrusted configCVE-2026-55441Highmise: Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repositoryCVE-2026-54557Mediummise: mise HTTP backend uses raw version path for install symlink destinationGHSA-74P7-6H78-GW8PHighskillctl: skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgeryCVE-2026-33646Criticalmise: Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)GHSA-JV2J-MQMW-XVV5Mediumsurrealdb: SurrealDB: Denial of Service via deep operator chainsGHSA-HV6H-HC26-Q48PMediumsurrealdb: SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversalsGHSA-H4H3-3RFJ-X6FQMediumsurrealdb: SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted fieldGHSA-CC8F-FCX3-GPJRHighsurrealdb: SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filterGHSA-H5RG-8P7F-47G2Mediumsurrealdb: SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key FetchCVE-2026-11941Mediumquiche: Cloudflare Quiche: Use-after-free in connection ID iterator FFI functionsCVE-2026-55832Mediumtract-onnx: tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx

Stop the waste.
Protect your environment with Kodem.