Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-43868Mediumthrift: Apache Thrift has a Memory Allocation with Excessive Size Value VulnerabilityGHSA-G27R-R6PH-VF5RLowsequoia-git: sequoia-git has broken hard revocation handlingGHSA-G38R-8GMR-GHRFCriticalmysten-metrics: `mysten-metrics` was removed from crates.io for malicious codeGHSA-QPRH-M6P3-HWXCCriticalsui-execution-cut: `sui-execution-cut` was removed from crates.io for malicious codeGHSA-83HF-93M4-RGWQHighhickory-recursor: Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context ElevationGHSA-82J2-J2CH-GFR8Highrustls-webpki: rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGCVE-2026-42199Mediumgrid: Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined BehaviorCVE-2026-42189Highrussh: russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handlerCVE-2026-42180Mediumlemmy_api_common: Lemmy has SSRF in /api/v3/post via Webmention dispatchCVE-2026-42181Mediumlemmy_api_common: Lemmy has SSRF and internal image disclosure in post link metadata via unvalidated og:imageCVE-2026-41676Highopenssl: rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1CVE-2026-41677Lowopenssl: rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized lengthCVE-2026-41678Highopenssl: rust-openssl has incorrect bounds assertion in aes key wrapCVE-2026-41681Highopenssl: rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length checkCVE-2026-41898Highopenssl: rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peerCVE-2026-40937Highrustfs: RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooksCVE-2026-34066Mediumnimiq-blockchain: nimiq-blockchain: Peer-triggerable panic during history syncCVE-2026-34068Mediumnimiq-transaction: nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledgeCVE-2026-34067Lownimiq-transaction: nimiq-transaction: Panic via `HistoryTreeProof` length mismatchCVE-2026-34065Highnimiq-primitives: nimiq-primitives: Node crash due to missing interlink validation in election macro block proposalsCVE-2026-34064Mediumnimiq-account: nimiq-account: Vesting insufficient funds error can panicCVE-2026-33471Criticalnimiq-block: nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncationCVE-2026-35378Lowcoreutils: uutils coreutils has an Incorrect Short Circuit Evaluation IssueCVE-2026-35380Mediumcoreutils: uutils coreutils has an Improper Input Validation Issue in its cut UtilityCVE-2026-35377Lowcoreutils: uutils coreutils has an Improper Input Validation Issue in its env Utility

Stop the waste.
Protect your environment with Kodem.