salvo
crates.io4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting salvopage 1 of 1
- CVE-2026-22256HIGHCVSS 8.8EG 8.8✓ Fixed in 0.88.12026-01-08
Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its inserted in the HTML without proper sanitation, this leads to…
- CVE-2026-22257HIGHCVSS 8.8EG 8.8✓ Fixed in 0.88.12026-01-08
Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the acc…
- CVE-2026-33241HIGHCVSS 7.5EG 7.5✓ Fixed in 0.89.32026-03-24
Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows atta…
- CVE-2026-33242HIGHCVSS 7.5EG 7.5✓ Fixed in 0.89.32026-03-24
Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated external attacker to bypass proxy routing…
Check whether salvo is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for salvo CVEs against the assets you own.
Start Free Scan →