Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-4GG8-GXPX-9RPHMediumuv: uv is vulnerable to arbitrary file write through entry point namesGHSA-3PV8-6F4R-FFG2Mediumtar: tar has a PAX header desynchronization issueGHSA-3CV2-H65G-FGMMMediumastral-tokio-tar: astral-tokio-tar has a PAX Header Desynchronization issueCVE-2026-46690Mediumunbounded-spsc: unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX raceCVE-2026-47144Mediumshamefile: Shamefile has an arbitrary file read via shamefile.yaml in shame nextCVE-2026-47128Mediumnono-cli: nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`CVE-2026-44726Highdeno: Deno's TLS retry copies stale upgrade hook, risking plaintext trafficCVE-2026-46703Criticalboxlite: Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the HostCVE-2026-46695Criticalboxlite: BoxLite: Permission Bypass Allows Modification of Read-Only FilesCVE-2026-46671Mediumonenote_parser: Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directoryCVE-2026-46673Highrussh-cryptovec: Russh: Unchecked CryptoVec allocation and growth handling is reachableCVE-2026-46654Highp3-challenger: Plonky3 MultiField32Challenger: transcript malleability and challenge entropy lossCVE-2026-46545Highnimiq-primitives: nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed itemCVE-2026-46543Mediumnimiq-blockchain: nimiq-blockchain: Genesis batch set requestCVE-2026-46542Mediumnimiq-keys: nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve pointsCVE-2026-46539Mediumnimiq-primitives: nimiq-primitives: BlockInclusionProof interlink issue when hops are emptyCVE-2026-45792Mediumrtk: RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLMCVE-2026-45784Mediumopenssl: rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersGHSA-M9P2-FXP5-V3FPMediumdiesel: Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`GHSA-Q8X8-JRHJ-FH9PMediumdiesel: Diesel: Possible unaligned data access for implementations of `SqliteAggregate`GHSA-FHVH-VW7H-9XF3Highlibcrux-ml-dsa: libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge CaseGHSA-HC3C-63HC-2R9FHighlibcrux-chacha20poly1305: libcrux: Potential Panic on Overlong Ciphertext BufferGHSA-FVH2-GM75-J4J7Highdynoxide-rs: dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transportGHSA-VFVV-C25P-M7MMMediumrkyv: rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code executionCVE-2026-40092Highnimiq-keys: nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT

Stop the waste.
Protect your environment with Kodem.