Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-C6PX-4GRW-HRJRHighbinjs_io: 'Read' on uninitialized memory may cause UBGHSA-5J8W-R7G8-5472Higharrow2: Arrow2 allows double free in `safe` codeGHSA-QGRP-8F3V-Q85PHigharrow: `FixedSizeBinaryArray` does not perform bound checks on accessing values and offsetsGHSA-H588-76VG-PRGJHigharrow: `DecimalArray` does not perform bound checks on accessing values and offsetsGHSA-QJ69-C89V-JWQ2Highash: Reading on uninitialized memory may cause UB ( `util::read_spv()` )GHSA-R7CJ-WMWV-HFW5Higharrow: `BinaryArray` does not perform bound checks on reading values and offsetsGHSA-7V4J-8WVR-V55RMediumarray-macro: `array!` macro is unsound when its length is impure constantGHSA-83GG-PWXF-JR89Mediumarray-macro: `array!` macro is unsound in presence of traits that implement methods it calls internallyGHSA-P2G9-94WH-65C2Mediumammonia: Space bug in `clean_text`GHSA-HV9V-7W3V-RJ6FHighacc_reader: `Read` on uninitialized buffer in `fill_buf()` and `read_up_to()`GHSA-HFXP-P695-629XHighabomonation: abomonation transmutes &T to and from &[u8] without sufficient constraintsGHSA-GFG9-X6PX-R7GRMediumplutonium: Library exclusively intended to obfuscate code.CVE-2020-25575Criticalfailure: Type confusion if __private_get_type_id__ is overridenCVE-2021-41641Highdeno: Link Following in DenoGHSA-RWF4-GX62-RQFWMediumcrossbeam: `MsQueue` `push`/`pop` use the wrong orderingsCVE-2022-29185Mediumtotp-rs: Observable Timing Discrepancy in totp-rsCVE-2021-43172Highroutinator: Routinator infinite loop vulnerabilityCVE-2021-3711Criticalopenssl-src: SM2 Decryption Buffer OverflowCVE-2021-3712Highopenssl-src: Read buffer overruns processing ASN.1 stringsCVE-2021-20332Mediummongodb: Exposure of Sensitive Information to an Unauthorized Actor in MongoDB Rust DriverCVE-2021-28305Criticaldiesel: Fix a use-after-free bug in diesels Sqlite backendCVE-2021-28031Criticalscratchpad: move_elements can double-free objects on panicCVE-2021-28027Criticalbam: Loading a bgzip block can write out of bounds if size overflows.CVE-2021-26954Mediumqwutils: insert_slice_clone can double drop if Clone panics.CVE-2021-25900Criticalsmallvec: Buffer overflow in SmallVec::insert_many

Stop the waste.
Protect your environment with Kodem.