HIGH8.8crates.io
GHSA-54m3-5fxr-2f3j· CVE-2026-22257Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names
Modified: 2/3/2026
package
pkg:crates.io/salvo
Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names
Modified: 2/3/2026
Salvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway Bypass
Modified: 3/25/2026
Salvo Affected by Denial of Service via Unbounded Memory Allocation in Form Data Parsing
Modified: 3/25/2026
Salvo is vulnerable to reflected XSS in the list_html function
Modified: 2/3/2026