RUST / SNIFFERCVE SCANNER

Know whatships with you.

Check your Cargo.lock for known
vulnerabilities. Know what needs attention.

↘
Cargo.lockLOCAL FILE / 01

Your lockfile stays on this device. Scanning runs in your browser with RustSec WebAssembly. No project code is executed.

Advisory freshness is checked before every scan. Service status

Choose a file to begin. No account needed.

Know what this scan can tell you.

Known dependency advisories. Not a source code audit or proof of exploitability.

Coverage & privacy, plainly explained

Only the selected lockfile is checked. Manifest and workspace membership, active features, target platforms, CISA exploitation data, and yanked crate checks are not evaluated in this web version. Advisory warnings are shown separately from vulnerabilities.

When available, reviewed GitHub advisories from OSV supplement RustSec. Aliases link overlapping reports; source disagreements are labeled and combined patch advice is withheld. Only supported crates.io version ranges are used. GitHub advisory data is adapted under CC BY 4.0; see source license and attribution. CISA KEV and EPSS are not included.

Each scan requests automatically checked RustSec and supplementary OSV data from this project's public GitHub feed. Its hash and metadata are verified before matching. If the feed is unavailable, a previously verified public snapshot or the bundled snapshot may be used and is clearly labeled. Data not verified within 14 days is rejected. Reports identify the upstream revision and verification time; coverage is never guaranteed.

Your lockfile and dependency list are not uploaded. The browser downloads scanner assets from this site and public advisory data from GitHub. Only public advisory data may be cached on this device, never your lockfile or report. Results stay in this tab unless you download them. This app adds no analytics or scan history; normal hosting access logs may still record page requests. Closing or reloading clears results.

Limits: 1 MiB, 5,000 locked packages, 25,000 dependency edges. Dependency tracing shows up to 20 immediate dependents and 3 example chains, at most 12 edges each. These are recorded lockfile relationships, not runtime call paths. Use the desktop app for richer context.

ResultsRUST DEPENDENCY ADVISORIES

The evidence starts here.

Run a scan to see dependency advisories and patch ranges.