MEDIUMcrates.io
GHSA-459f-x8vq-xjjm· CVE-2025-67487Static Web Server vulnerable to a symbolic link path traversal
Modified: 12/9/2025
package
pkg:crates.io/static-web-server
Static Web Server vulnerable to a symbolic link path traversal
Modified: 12/9/2025
Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernames
Modified: 2/23/2026
static-web-server vulnerable to stored Cross-site Scripting in directory listings via file names
Modified: 5/1/2024