Skip to content

Package advisories

crates.io

29advisory rows26advisories22packagesRSSas of the 2026-09-07 snapshot

An advisory is the GHSA entry a Dependabot alert links to; GitHub-reviewed only. One row is one change to one package: 10 fixed-in version changed, 19 package added later.

No rate: 35,259 advisories were compared across every ecosystem together, and the analysis carries no count of how many were crates.io, so nothing here divides one number by the other.

Kind of change

29 counted rows, shown as 6 lines because the same change repeated is shown once · newest advisory first

Changes to GitHub-reviewed advisories naming a package in crates.io. Each row gives the kind of change and the advisory it happened to. Where the same change was made to several advisories or packages at once, one row stands for all of them, says how many, and opens to every one. Then the ecosystem and package, what the advisory said beside what it says now, GitHub's severity level, and the date the advisory was published.
Package, The package the change names, or where one row stands for the same change across several packages, how many.Kind of changeAdvisory, The advisory id, or where one row stands for the same change made to several advisories, how many it stands for. An advisory id links to GitHub, and a CVE id is shown beside it where the advisory names one.What changedSeverity, GitHub's severity level for the advisory as it stands today: low, moderate, high or critical. Where one row stands for advisories at more than one level, it says how many levels, never one of them.Advisory published, The date the advisory was published. Every lag on this source is measured from it, and it is a third clock beside the CVE catalog's publication date and the date CISA added an entry to KEV. Two kinds of change also carry a date of their own: a withdrawal states its own timestamp, and a changed fix version is dated by reading back through the dated saves of the advisory file until the one where the version first reached the value it has today. A package added and a severity changed leave no commit of their own to date, so for those the date of the change is not recorded at all. That is absence, never same-day.
zebra-scriptAdvisory fix version movedGHSA-8m29-fpq5-89jjCVE-2026-41583stated at publication 5.0.1, now states 5.0.2critical2026-04-18
16 packages19 rows, one per advisory and packagePackage added to advisory17 advisoriesnot named as affected when the advisory was published, now names libcrux-ml-dsa and 15 more4 severity levels2021-08-25 to2025-12-04
libcrux-ml-dsasame kind of edit as the line aboveGHSA-2cgv-28vr-rv6jnot named as affected when the advisory was published, now names libcrux-ml-dsahigh2025-12-04
libcrux-ml-kemsame kind of edit as the line aboveGHSA-2cgv-28vr-rv6jnot named as affected when the advisory was published, now names libcrux-ml-kemhigh2025-12-04
tokio-tarsame kind of edit as the line aboveGHSA-j5gw-2vrg-8fgxCVE-2025-62518not named as affected when the advisory was published, now names tokio-tarhigh2025-10-21
wasmtimesame kind of edit as the line aboveGHSA-fm79-3f68-h2fcCVE-2025-53901not named as affected when the advisory was published, now names wasmtimelow2025-07-18
matrix-sdk-sqlitesame kind of edit as the line aboveGHSA-275g-g844-73jhCVE-2025-53549not named as affected when the advisory was published, now names matrix-sdk-sqlitemoderate2025-07-10
tor-circmgrsame kind of edit as the line aboveGHSA-9328-gcfq-p269CVE-2024-35312not named as affected when the advisory was published, now names tor-circmgrhigh2024-05-18
denosame kind of edit as the line aboveGHSA-m4pq-fv2w-6hrwCVE-2024-27936not named as affected when the advisory was published, now names denohigh2024-03-05
libwebp-syssame kind of edit as the line aboveGHSA-j7hp-h8jx-5pprCVE-2023-4863not named as affected when the advisory was published, now names libwebp-syshigh2023-09-12
11 more rows in this change are not listed here. Open all 19 rows
2 packagesAdvisory fix version movedGHSA-27vq-hv74-7cqpstated at publication 2.1.3, now states 2.1.4low2024-12-16
surrealdbAdvisory fix version movedGHSA-27vq-hv74-7cqpCVE-2024-58356same change as the line abovelow2024-12-16
surrealdb-coreAdvisory fix version movedGHSA-27vq-hv74-7cqpCVE-2024-58356same change as the line abovelow2024-12-16
dbnAdvisory fix version movedGHSA-pfr9-2p92-qrhqstated at publication 0.22.0, now states 0.22.1moderate2024-10-09
simple-wayland-hotkey-daemonAdvisory fix version moved2 advisoriesstated at publication 1.1.7, now states 1.2.02 severity levels2022-04-08
simple-wayland-hotkey-daemonsame kind of edit as the line aboveGHSA-h6xw-mghq-7523CVE-2022-27819same change as the line abovemoderate2022-04-08
simple-wayland-hotkey-daemonsame kind of edit as the line aboveGHSA-r3r5-jhw6-4634CVE-2022-27818same change as the line abovecritical2022-04-08
actix-webAdvisory fix version moved4 advisoriesstated at publication 0.7.15, now states 0.7.192 severity levels2021-08-25 to2022-01-06
actix-websame kind of edit as the line aboveGHSA-9qj6-4rfq-vm84CVE-2018-25024same change as the line abovecritical2022-01-06
actix-websame kind of edit as the line aboveGHSA-7x36-h62w-vw65CVE-2018-25026same change as the line abovecritical2022-01-06
actix-websame kind of edit as the line aboveGHSA-fgfm-hqjw-3265CVE-2018-25025same change as the line abovecritical2022-01-06
actix-websame kind of edit as the line aboveGHSA-w65j-g6c7-g3m4same change as the line abovemoderate2021-08-25

29 rows, grouped into 6, all on this page

Every change counted from this source is on this page, so an advisory with no row here had no change of that kind. No finding here is not an all clear. It means this check found nothing in the history it can see, not that nothing happened.

A grouped row is the same change, repeated. Where one change was made to many packages or many advisories, the advisory column says how many it stands for instead of naming one, and opens to every one of them. It may have been one edit or many: what the grouping states is that the change is identical, not that it was made in one act.

A fixed-in version is compared within one release branch, keyed by the range's introduced value. An advisory listing a fix for 4.1.x and another for 4.2.x states two of them, and taking the highest version across the whole package would report a newly added branch as though an existing branch's fix had changed.

3 more advisories that name a package in crates.io had the severity changed, or the whole advisory withdrawn. None of it is counted in any figure above. Open to read it.

A severity level and a withdrawal belong to the whole advisory. The advisory database records neither against a package, so neither can be attributed to an ecosystem. These 3 rows are here for one reason: the same advisory also names a package in crates.io in the table above. The other 3,177 of the 3,180 cannot be placed in an ecosystem at all.

Severity changes and withdrawals recorded against advisories that also name a package in crates.io. These rows name no ecosystem of their own and are not counted in this page's ecosystem figures.
Kind of changeAdvisoryWhat changedSeverityAdvisory published
Advisory severity changedGHSA-j7hp-h8jx-5pprCVE-2023-4863stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-09-12
Advisory severity changedGHSA-mjvm-mhgc-q4gpCVE-2022-36008stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.moderate2022-08-18
Advisory severity changedGHSA-r3r5-jhw6-4634CVE-2022-27818stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-04-08

Data sources and quality

Every figure on this page counts rows keyed to a GitHub advisory, naming an ecosystem and a package. None of them counts CVE records, and none is ever added to the record counts elsewhere on this site. One row is one difference between the advisory as it was first published and the same advisory today. Rows, advisories and packages are three different numbers and are never added.

Not checked: GitHub-reviewed advisories only. An advisory GitHub never reviewed, and an ecosystem it does not review, produce no row at all, so an ecosystem missing from these figures is not evidence that its advisories held.

How advisories are compared, in full →

Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.

Shipped snapshot computed 2026-09-07 from catalog commit 67b73cc1e9c6. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.