cargo package reportIs cargo-download safe?
1 known vulnerability.
// reach0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.
epsschance of exploitation in 30 days
xyz scoreCyberXYZ composite out of 10
fig. 01 — RUSTSEC-2021-0133, the advisory selected below
// 1 advisories
RUSTSEC-2021-0133
UNKNOWNThe cargo download subcommand (via cargo-download crate) is broken and maintainer has disappeared from GitHub and hasn't had any commits for a year.
Using this downloader will result to corrupted crates.
Maintainer has not responded to maintenance takeover.
Just use wget / curl directly.
Checked 2026-10-04 at 01:15 UTC. The most recent advisory here was published 2021-12-25. Updated continuously from NVD, GHSA, OSV and CNA feeds.