Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45374Criticaldeepseek-tui: DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project FilesCVE-2026-45373Highdeepseek-tui: DeepSeek TUI has SSRF‌ IPV6 bypassCVE-2026-45311Criticaldeepseek-tui: DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without ApprovalCVE-2026-45310Highdeepseek-tui: DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url ToolGHSA-429Q-FHH4-R6HJHighanchor-lang: Anchor: `InterfaceAccount` allows account substitution between unexpected typesCVE-2026-45137Highanchor-lang: Anchor: Program<'info, System> is not properly validatedGHSA-88Q9-CMP2-C2VQMediumoxidize-pdf: oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)GHSA-G588-CJG3-6G78Mediumsteamworks: Steamworks game clients/servers using P2P authentication vulnerable to denial of serviceCVE-2026-44983Highsmallbitvec: smallbitvec: Integer overflow in safe API leads to heap buffer overflowCVE-2026-44499Highzebrad: Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer PoisoningGHSA-PVMV-CWG8-V6C8Criticalzebrad: Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding outputCVE-2026-44662Mediumopenssl: rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-paddingGHSA-CWFQ-RFCR-8HMPCriticalzebrad: Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding OutputsCVE-2026-44497Criticalzebra-script: Zebra has Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale BufferCVE-2026-44500Mediumzebra-network: Zebra Vulnerable to Allocation Amplification in Inbound Network DeserializersCVE-2026-44498Criticalzebrad: Zebra's Block Validator Undercounts Coinbase and P2SH SigopsGHSA-W5P8-4JCX-2J6RMediumimageproc: imageproc: integer overflow in kernel size check leads to out-of-bounds readGHSA-QG8R-F7X3-25F7Mediumimageproc: imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic samplingGHSA-5QV7-J6W5-FR4MMediumimageproc: imageproc has fragile bounds check when sampling from imageGHSA-Q2QQ-HMJ6-3WPPMediumhickory-proto: hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compressionGHSA-3V94-MW7P-V465Highhickory-proto: hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responsesGHSA-FPF5-4JW8-67X8Highrust-zserio: rust-zserio has Unbounded Memory AllocationCVE-2026-44216Mediumwasmtime: wasmtime has a panic when allocating a table exceeding the size of the host's address spaceGHSA-FF9Q-RM55-Q7QRLowdiesel-async: diesel-async may expose uninitialized padding bytes for MySQL temporal columnsCVE-2026-44471Highgix-fs: gix-fs: Symlink prefix-reuse allows worktree escape during checkout

Stop the waste.
Protect your environment with Kodem.