Your dependencies cross-checked against the OSV vulnerability database.
-
Worth fixing RUSTSEC-2026-0194 Quadratic run time when checking a start tag for duplicate attribute names
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/demos/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
Worth fixing RUSTSEC-2026-0195 Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/demos/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
Worth fixing RUSTSEC-2026-0194 Quadratic run time when checking a start tag for duplicate attribute names
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
Worth fixing RUSTSEC-2026-0195 Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
Worth fixing RUSTSEC-2023-0071 Marvin Attack: potential key recovery through timing sidechannels
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole (CVE-2023-49092). Fix: Update that package to its patched version.
-
Worth fixing GHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/pnpm-lock.yaml
A package you depend on has a known security hole (CVE-2026-14257). Fix: Update that package to its patched version.
-
Worth fixing RUSTSEC-2026-0194 Quadratic run time when checking a start tag for duplicate attribute names
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/tests/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
Worth fixing RUSTSEC-2026-0195 Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/tests/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2023-0089 atomic-polyfill is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2025-0141 Bincode is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2024-0436 paste - no longer maintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2026-0206 `rustybuzz` is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2026-0192 `ttf-parser` is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2025-0052 async-std has been discontinued
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/demos/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2025-0141 Bincode is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/demos/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2026-0221 `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/demos/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2024-0436 paste - no longer maintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/demos/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2026-0206 `rustybuzz` is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/demos/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2026-0192 `ttf-parser` is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/demos/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2025-0141 Bincode is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2025-0141 Bincode is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2026-0221 `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2024-0436 paste - no longer maintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2026-0206 `rustybuzz` is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.
-
FYI RUSTSEC-2026-0192 `ttf-parser` is unmaintained
/workdirs/scan-510c540c-3b3d-4473-a5f3-8f14c8656d41/examples/Cargo.lock
A package you depend on has a known security hole. Fix: Update that package to its patched version.