Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Package ecosystem crates.io. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 4 | 4 | 3 |
█▁█▁
2026-05 2 · 2026-06 0 · 2026-07 2 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-58389 | 8.7 | 63.0 | — | Apache Thrift: Rust binary protocol non-strict path missing string size limit |
| CVE-2026-5222 | 2.3 | 39.4 | — | Cargo can be coerced to share credentials between registries |
| CVE-2026-60080 | 7.3 | 35.6 | — | Apache Fory: Rust MetaString heap use-after-free |
| CVE-2026-5223 | 6.5 | 22.1 | — | Crates in third party registries can override the cached source of other crates |
| Package | CVEs |
|---|---|
| cargo | 2 |
| fory-core | 1 |
| thrift | 1 |