Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-QXRW-F6FH-34R7Mediumlemmy_api: Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated usersGHSA-QCXQ-75WR-5CM8Highldap3_proto: ldap3_proto has LDAP Filter stack exhaustionGHSA-84JC-3HJ2-HWC7Mediumkanidmd_lib: kanidmd_lib: Image upload validators run before authorization; PNG validator panics on malformed inputCVE-2026-46689Highscim_proto: scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustionGHSA-53HJ-R94P-8C8FLowkanidm: Kanidm has non-constant-time comparison of OAuth2 client_secretGHSA-GPXG-FX2G-QXJ2Mediumkanidm: Kanidm: Stored HTML injection in "passkey-enrolment" partial via displayname → htmx-driven authenticated request forgeryGHSA-22W3-693W-X895Lowwebauthn-rs-core: webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowedGHSA-95Q8-X6R6-672MMediumlemmy_api: Lemmy may expose private community data through community, saved, liked, and modlog API viewsGHSA-JMXC-HHWX-GVV3Mediumlemmy_api: Private Lemmy instances expose multi-community metadata without authenticationCVE-2026-42559Highrmcp: rmcp Streamable HTTP server transport has a DNS rebinding vulnerabilityGHSA-2P6R-X3VV-XQM2Lowrpassword: rpassword affected by partial password reveal when input is interrupted GHSA-XX64-WWV2-HCQQLowastral-tokio-tar: astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinksGHSA-FP55-JW48-C537Mediumastral-tokio-tar: astral-tokio-tar is Vulnerable to PAX Header DesynchronizationCVE-2026-42184Mediumtauri: Tauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC CommandsCVE-2026-42327Highopenssl: rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsGHSA-MM2Q-QCMX-GW4WHighrustfs: RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeoverGHSA-FR8X-3VFX-F45HHighgitoxide: gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repositoryGHSA-PG4W-G64P-QWHJHighgitoxide: gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repositoryGHSA-X494-MJ8G-CJ27Highgix-pack: gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack dataCVE-2026-40034Highgix: gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodulesGHSA-P3HW-MV63-RF9WHighgix: gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosureGHSA-9857-6MW7-FQ2MMediumgix-transport: gix-transport: HTTP credentials leaked to redirected host in curl backendCVE-2026-6967Hightough: awslabs/tough is Missing Delegated Metadata ValidationCVE-2026-6966Hightough: awslabs/tough Delegated Roles have a Signature Threshold BypassGHSA-H5X4-M2QF-R4F2Highdiesel: Diesel's SQLite backend has possible UTF-8 corruption

Stop the waste.
Protect your environment with Kodem.