CVE Tools

Crates-io

1,273 CVEs tracked since 2016. Since Aug 2021, 1 of them reached CISA KEV.

Crates-io CVEs per month

Aug 2021 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Crates-io CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-08900
2021-0950
2021-1040
2021-1150
2021-12550
2022-0130
2022-0240
2022-0370
2022-0460
2022-0560
2022-06610
2022-0770
2022-08190
2022-09190
2022-1050
2022-11120
2022-12110
2023-0190
2023-02180
2023-03null or fewer
2023-0470
2023-0540
2023-06110
2023-0750
2023-08100
2023-09171
2023-1040
2023-1160
2023-12110
2024-01170
2024-02180
2024-03150
2024-0490
2024-05140
2024-0660
2024-07140
2024-08140
2024-09110
2024-10120
2024-11210
2024-12230
2025-01110
2025-02130
2025-03180
2025-04240
2025-05250
2025-06150
2025-07360
2025-08110
2025-09160
2025-10170
2025-11120
2025-12120
2026-01320
2026-02400
2026-03500
2026-04180
2026-05440
2026-06100
2026-07410
2026-08100

Products

The products that kept showing up in Crates-io's monthly top three, with their CVEs summed over those months.

  1. Surrealdb478 months
  2. Ckb226 months
  3. Deno186 months
  4. Openssl-src165 months
  5. Wasmtime125 months
  6. Apollo-router94 months
  7. Rustfs92 months
  8. Rusqlite71 month
  9. Tough72 months
  10. Vaultwarden72 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Crates-io.

  1. GHSA-2jx3-ff3v-j7jjyara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB—
  2. GHSA-m3wp-48jr-vr4g mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS—
  3. GHSA-wfgq-w7cq-qj7jmistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url—
  4. GHSA-2vh6-hw4j-32wwgix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)—
  5. GHSA-fx4f-mhw4-qm7jvibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths—
  6. GHSA-3gjw-f78c-vvpwtokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service—
  7. GHSA-rgqc-3x5p-6gwgpostgres-protocol: Panic decoding a malformed `hstore` value allows denial of service—
  8. GHSA-5x78-73v4-xg6wpostgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service—
  9. GHSA-mc9m-6fm9-pghcZoo Design Studio: Memory-corruption in memory handling of lib-kcl—
  10. GHSA-jgvr-6x5w-hx5wZoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service—
  11. GHSA-qwgh-2vcv-g2f7block_buffer: panic corrupts inline buffer position—
  12. GHSA-vjf8-9fx6-mv6xTriton VM Soundness Vulnerability due to Missing Constraint—
  13. GHSA-8rw6-p7m8-63jpSurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users—
  14. GHSA-3whf-vgf2-9w6gzaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit—
  15. GHSA-6xx4-9wp6-65p7skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source—

The record

Peak rank
#4 in Dec 2020
Busiest month shown
Aug 2021, 90 CVEs
Months with a KEV entry
1 since Aug 2021
Monthly snapshots
72 since 2016
Crates-io's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store