boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

crates.io

Package ecosystem crates.io. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals
CVEs all-timeCVEs YTDPackages affected
443

Monthly trend

█▁█▁

2026-05 2 · 2026-06 0 · 2026-07 2 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-583898.763.0Apache Thrift: Rust binary protocol non-strict path missing string size limit
CVE-2026-52222.339.4Cargo can be coerced to share credentials between registries
CVE-2026-600807.335.6Apache Fory: Rust MetaString heap use-after-free
CVE-2026-52236.522.1Crates in third party registries can override the cached source of other crates

Most-affected packages

Packages with the most advisories
PackageCVEs
cargo2
fory-core1
thrift1