Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-jv4x-jv3h-qff5
  • crates.io/deno
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor 2 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-m65q-v92h-cm7q
  • crates.io/users
users may append `root` to group listings 2 days ago
  • No fix available
  • Severity - 7.1 (High)
GHSA-pr59-jjr4-gcf6
  • crates.io/anon-vec
anon-vec lacks sufficient checks in public API 2 days ago
  • No fix available
GHSA-8vxj-4cph-c596
  • crates.io/deno
  • crates.io/deno_node
Deno has --allow-read / --allow-write permission bypass in `node:sqlite` 2 days ago
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-7w8p-chxq-2789
  • crates.io/deno
  • crates.io/deno_runtime
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables 2 days ago
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-xqxc-x6p3-w683
  • crates.io/deno
  • crates.io/deno_runtime
Deno run with --allow-read and --deny-read flags results in allowed 2 days ago
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-2x3r-hwv5-p32x
  • crates.io/deno
  • crates.io/deno_node
Deno's AES GCM authentication tags are not verified 2 days ago
  • Fix available
  • Severity - 7.7 (High)
GHSA-wv8j-m3hx-924j
  • crates.io/arrow2
Arrow2 allows out of bounds access in public safe API 30 May
  • No fix available
  • Severity - 8.7 (High)
GHSA-5r4r-9fgh-pw53
  • crates.io/memory_pages
memory_pages division by zero 24 May
  • No fix available
  • Severity - 2.9 (Low)
GHSA-6v24-6wgf-8vj6
  • crates.io/process_lock
process_lock has a Potential Unsound issue in unlock 24 May
  • No fix available
  • Severity - 2.9 (Low)
GHSA-cm3g-qm4h-xm6m
  • crates.io/scsir
SCSIR has a Potential Unsound Issue in WriteSameCommand 24 May
  • No fix available
  • Severity - 2.9 (Low)
GHSA-mqwx-r894-9hfp
  • crates.io/process-sync
Process Sync has a Potential Unsound Issue in SharedMutex 24 May
  • No fix available
  • Severity - 2.9 (Low)
GHSA-3qmp-g57h-rxf2
  • crates.io/pingora-core
Pingora Request Smuggling and Cache Poisoning 22 May
  • Fix available
  • Severity - 7.4 (High)
RUSTSEC-2025-0037
  • crates.io/pingora-core
Pingora Request Smuggling and Cache Poisoning 22 May
  • Fix available
RUSTSEC-2025-0036
  • crates.io/surf
surf is unmaintained 17 May
  • No fix available
GHSA-gg76-hg3v-5q6c
  • crates.io/macroquad
macroquad vulnerable to multiple soundness issues 15 May
  • No fix available
  • Severity - 8.7 (High)