Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
Cargo crates in third party registries can override the cached source of other crates Moderate
CVE-2026-5223 was published for cargo (Rust) Jun 26, 2026
christos-spearbit Credited to christos-spearbit, arlosi, emilyalbini, cuviper, and Manishearth arlosi arlosi
emilyalbini emilyalbini cuviper cuviper Manishearth Manishearth
Cargo can be coerced to share credentials between registries Low
CVE-2026-5222 was published for cargo (Rust) Jun 26, 2026
christos-spearbit Credited to christos-spearbit, arlosi, weihanglo, ehuss, emilyalbini, cuviper, and Manishearth arlosi arlosi
weihanglo weihanglo ehuss ehuss emilyalbini emilyalbini cuviper cuviper Manishearth Manishearth
Manishearth Credited to Manishearth
Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports Low
CVE-2023-40030 was published for cargo (Rust) Aug 24, 2023
emilyalbini Credited to emilyalbini, cuviper, remkop22, ehuss, weihanglo, Manishearth, and iusx cuviper cuviper
remkop22 remkop22 ehuss ehuss weihanglo weihanglo Manishearth Manishearth iusx iusx
Cargo not respecting umask when extracting crate archives High
CVE-2023-38497 was published for cargo (Rust) Aug 3, 2023
addisoncrump Credited to addisoncrump, emilyalbini, weihanglo, ehuss, cuviper, and Manishearth emilyalbini emilyalbini
weihanglo weihanglo ehuss ehuss cuviper cuviper Manishearth Manishearth
ProTip! Advisories are also available from the GraphQL API