Crates-io
1,273 CVEs tracked since 2016. Since Aug 2021, 1 of them reached CISA KEV.
Crates-io CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-08 | 90 | 0 |
| 2021-09 | 5 | 0 |
| 2021-10 | 4 | 0 |
| 2021-11 | 5 | 0 |
| 2021-12 | 55 | 0 |
| 2022-01 | 3 | 0 |
| 2022-02 | 4 | 0 |
| 2022-03 | 7 | 0 |
| 2022-04 | 6 | 0 |
| 2022-05 | 6 | 0 |
| 2022-06 | 61 | 0 |
| 2022-07 | 7 | 0 |
| 2022-08 | 19 | 0 |
| 2022-09 | 19 | 0 |
| 2022-10 | 5 | 0 |
| 2022-11 | 12 | 0 |
| 2022-12 | 11 | 0 |
| 2023-01 | 9 | 0 |
| 2023-02 | 18 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 7 | 0 |
| 2023-05 | 4 | 0 |
| 2023-06 | 11 | 0 |
| 2023-07 | 5 | 0 |
| 2023-08 | 10 | 0 |
| 2023-09 | 17 | 1 |
| 2023-10 | 4 | 0 |
| 2023-11 | 6 | 0 |
| 2023-12 | 11 | 0 |
| 2024-01 | 17 | 0 |
| 2024-02 | 18 | 0 |
| 2024-03 | 15 | 0 |
| 2024-04 | 9 | 0 |
| 2024-05 | 14 | 0 |
| 2024-06 | 6 | 0 |
| 2024-07 | 14 | 0 |
| 2024-08 | 14 | 0 |
| 2024-09 | 11 | 0 |
| 2024-10 | 12 | 0 |
| 2024-11 | 21 | 0 |
| 2024-12 | 23 | 0 |
| 2025-01 | 11 | 0 |
| 2025-02 | 13 | 0 |
| 2025-03 | 18 | 0 |
| 2025-04 | 24 | 0 |
| 2025-05 | 25 | 0 |
| 2025-06 | 15 | 0 |
| 2025-07 | 36 | 0 |
| 2025-08 | 11 | 0 |
| 2025-09 | 16 | 0 |
| 2025-10 | 17 | 0 |
| 2025-11 | 12 | 0 |
| 2025-12 | 12 | 0 |
| 2026-01 | 32 | 0 |
| 2026-02 | 40 | 0 |
| 2026-03 | 50 | 0 |
| 2026-04 | 18 | 0 |
| 2026-05 | 44 | 0 |
| 2026-06 | 10 | 0 |
| 2026-07 | 41 | 0 |
| 2026-08 | 10 | 0 |
Products
The products that kept showing up in Crates-io's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Crates-io.
- GHSA-2jx3-ff3v-j7jjyara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB—
- GHSA-m3wp-48jr-vr4g mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS—
- GHSA-wfgq-w7cq-qj7jmistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url—
- GHSA-2vh6-hw4j-32wwgix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)—
- GHSA-fx4f-mhw4-qm7jvibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths—
- GHSA-3gjw-f78c-vvpwtokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service—
- GHSA-rgqc-3x5p-6gwgpostgres-protocol: Panic decoding a malformed `hstore` value allows denial of service—
- GHSA-5x78-73v4-xg6wpostgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service—
- GHSA-mc9m-6fm9-pghcZoo Design Studio: Memory-corruption in memory handling of lib-kcl—
- GHSA-jgvr-6x5w-hx5wZoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service—
- GHSA-qwgh-2vcv-g2f7block_buffer: panic corrupts inline buffer position—
- GHSA-vjf8-9fx6-mv6xTriton VM Soundness Vulnerability due to Missing Constraint—
- GHSA-8rw6-p7m8-63jpSurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users—
- GHSA-3whf-vgf2-9w6gzaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit—
- GHSA-6xx4-9wp6-65p7skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source—
The record
- Peak rank
- #4 in Dec 2020
- Busiest month shown
- Aug 2021, 90 CVEs
- Months with a KEV entry
- 1 since Aug 2021
- Monthly snapshots
- 72 since 2016