Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
crates.io
Package ecosystem crates.io. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
Totals
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 14 | 14 | 11 |
Monthly trend
▃▁▃▁█▂
2026-05 2 · 2026-06 0 · 2026-07 2 · 2026-08 0 · 2026-09 9 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-58389 | 8.7 | 62.6 | — | Apache Thrift: Rust binary protocol non-strict path missing string size limit |
| CVE-2026-60080 | 7.3 | 51.0 | — | Apache Fory: Rust MetaString heap use-after-free |
| CVE-2026-89146 | 8.7 | 48.5 | — | libp2p-rendezvous through 0.17.1 Denial of Service via Unbounded Registration TTL in Di… |
| CVE-2026-5222 | 2.3 | 40.6 | — | Cargo can be coerced to share credentials between registries |
| CVE-2026-95624 | 6.8 | 37.0 | — | Tauri framework v2 malicious downgrade via allow_downgrades from frontend code |
| CVE-2026-82458 | 8.7 | 34.8 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-5223 | 6.5 | 33.8 | — | Crates in third party registries can override the cached source of other crates |
| CVE-2026-93657 | 8.7 | 32.3 | — | hickory-resolver before 0.26.2 DNSSEC Validation Bypass |
| CVE-2026-95626 | 8.3 | 18.6 | — | Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an … |
| CVE-2026-97875 | 8.1 | 16.2 | — | DNS rebinding vulnerability in rojo serve HTTP API |
| CVE-2026-95623 | 5.6 | 13.6 | — | Tauri framework v2 SSRF Protection Bypass via HTTP Redirects |
| CVE-2026-95627 | 7.7 | 9.3 | — | Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-contro… |
| CVE-2026-95625 | 5.9 | 4.2 | — | Tauri framework v2 missing updater signature version number validation can be exploited… |
| CVE-2026-93658 | 7.3 | 2.8 | — | uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid |
Most-affected packages
| Package | CVEs |
|---|---|
| cargo | 2 |
| tauri-plugin-updater | 2 |
| thrift | 2 |
| coreutils | 1 |
| fory-core | 1 |
| hickory-resolver | 1 |
| libp2p-rendezvous | 1 |
| rojo | 1 |
| tauri | 1 |
| tauri-plugin-dialog | 1 |
| tauri-plugin-http | 1 |