Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-41138Mediumpallet-ethereum: Validity check missing in FrontierCVE-2021-20319Highcoreos-installer: coreos-installer improperly verifies GPG signature when decompressing gzipped artifactCVE-2020-26281Mediumasync-h1: Async-h1 request smuggling possible with long unread bodiesCVE-2021-32619Criticaldeno: Deno's static imports inside dynamically imported modules do not adhere to permission checksCVE-2021-39219Mediumwasmtime: Wrong type for `Linker`-define functions when used across two `Engine`sCVE-2021-39218Mediumwasmtime: Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime CVE-2021-39216Mediumwasmtime: Use after free passing `externref`s to Wasm in WasmtimeCVE-2021-39228Mediumtremor-script: Memory Safety Issue when using patch or merge on state and assign the result back to stateCVE-2021-28035Criticalstack_dst: Drop of uninitialized memory in stack_dstCVE-2021-28034Criticalstack_dst: Double free in stack_dstCVE-2021-28029Hightoodee: Uninitialized memory access in toodeeCVE-2021-28028Criticaltoodee: Double free in toodeeCVE-2021-39193Mediumpallet-ethereum: Transaction validity oversight in pallet-ethereumCVE-2021-32629Highcranelift-codegen: Memory access due to code generation flaw in Cranelift moduleCVE-2021-31996Highalgorithmica: Double free in algorithmicaCVE-2021-31919Highrkyv: Use of uninitialized buffer in rkyvCVE-2021-31155Highpleaser: Permissions bypass in pleaserCVE-2021-31154Highpleaser: Permissions bypass in pleaserCVE-2021-31153Lowpleaser: File exposure in pleaserCVE-2021-36376Highgit-delta: Relative Path Traversal in git-deltaCVE-2021-36753Highbat: Uncontrolled Search Path Element in sharkdp/batCVE-2020-36212Highabi_stable: Update unsound DrainFilter and RString::retainCVE-2020-36213Highabi_stable: Update unsound DrainFilter and RString::retainCVE-2020-25574Highhttp: Integer Overflow/Infinite Loop in the http crateCVE-2020-13759Highvm-memory: Improper Synchronization and Race Condition in vm-memory

Stop the waste.
Protect your environment with Kodem.