This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate poem-derive

No external dependencies! 🙌

Crate poem

Dependencies

(48 total, 7 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 hyper^1.0.01.6.0up to date
 hyper-util^0.1.60.1.11up to date
 http-body-util^0.1.00.1.3up to date
 parking_lot^0.12.00.12.3up to date
 pin-project-lite^0.2.70.2.16up to date
 percent-encoding^2.1.02.3.1up to date
 smallvec^1.6.11.15.0up to date
 headers^0.4.00.4.0up to date
 rfc7239^0.1.00.1.3up to date
 wildmatch^22.4.0up to date
 sync_wrapper^1.0.01.0.2up to date
 multer^3.0.03.1.0up to date
 tokio-tungstenite^0.250.26.2out of date
 rustls-pemfile^2.0.02.2.0up to date
 async-compression^0.4.00.4.22up to date
 tower^0.4.80.5.2out of date
 time^0.30.3.41up to date
 mime_guess^2.0.32.0.5up to date
 rand^0.9.00.9.0up to date
 redis^0.280.29.5out of date
 cookie^0.180.18.1up to date
 opentelemetry-http^0.29.00.29.0up to date
 opentelemetry-semantic-conventions^0.29.00.29.0up to date
 opentelemetry-prometheus^0.29.00.29.1up to date
 prometheus^0.13.00.14.0out of date
 opentelemetry^0.29.00.29.1up to date
 tempfile^3.2.03.19.1up to date
 priority-queue^2.0.22.3.1up to date
 tokio-native-tls^0.3.00.3.1up to date
 tokio-openssl^0.6.30.6.5up to date
 openssl ⚠️^0.10.710.10.72maybe insecure
 csrf^0.5.00.5.0up to date
 httpdate^1.0.21.0.3up to date
 sse-codec^0.3.20.3.2up to date
 fluent^0.16.00.16.1up to date
 fluent-langneg^0.13.00.14.1out of date
 fluent-syntax^0.11.00.11.1up to date
 unic-langid^0.9.00.9.5up to date
 intl-memoizer^0.5.10.5.2up to date
 ring^0.17.140.17.14up to date
 rcgen^0.12.00.13.2out of date
 x509-parser^0.16.00.17.0out of date
 tokio-metrics^0.40.4.0up to date
 rust-embed^8.08.7.0up to date
 hex^0.40.4.3up to date
 anyhow^1.0.01.0.98up to date
 eyre^0.6.120.6.12up to date
 uuid^1.8.01.16.0up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 async-stream^0.3.20.3.6up to date

Crate poem-openapi-derive

No external dependencies! 🙌

Crate poem-openapi

Dependencies

(15 total, 1 outdated)

CrateRequiredLatestStatus
 derive_more^1.02.0.1out of date
 num-traits^0.2.140.2.19up to date
 itertools^0.14.00.14.0up to date
 email_address^0.2.10.2.9up to date
 hostname-validator^1.1.01.1.1up to date
 uuid^1.1.01.16.0up to date
 url^2.2.22.5.4up to date
 bson^2.0.02.14.0up to date
 rust_decimal^1.22.01.37.1up to date
 humantime^2.1.02.2.0up to date
 ipnet^2.7.12.11.0up to date
 prost-wkt-types^0.6.00.6.0up to date
 geo-types^0.7.120.7.16up to date
 geojson^0.24.10.24.2up to date
 sqlx^0.8.30.8.4up to date

Crate poem-lambda

Dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 lambda_http^0.13.00.14.0out of date

Crate poem-grpc-build

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 prettyplease^0.2.90.2.32up to date
 prost-build^0.13.10.13.5up to date

Crate poem-grpc

Dependencies

(13 total, all up-to-date)

CrateRequiredLatestStatus
 async-stream^0.3.30.3.6up to date
 itoa^1.0.21.0.15up to date
 percent-encoding^2.1.02.3.1up to date
 prost^0.13.10.13.5up to date
 prost-types^0.13.10.13.5up to date
 fastrand^2.0.02.3.0up to date
 hyper^1.0.01.6.0up to date
 hyper-util^0.1.100.1.11up to date
 http-body-util^0.1.00.1.3up to date
 tower-service^0.3.20.3.3up to date
 webpki-roots^0.260.26.8up to date
 async-compression^0.4.00.4.22up to date
 sync_wrapper^1.0.01.0.2up to date

Crate poem-mcpserver

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 pin-project-lite^0.2.160.2.16up to date

Crate poem-mcpserver-macros

No external dependencies! 🙌

Security Vulnerabilities

openssl: Use-After-Free in `Md::fetch` and `Cipher::fetch`

RUSTSEC-2025-0022

When a Some(...) value was passed to the properties argument of either of these functions, a use-after-free would result.

In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to CString::drop's behavior).

The maintainers thank quitbug for reporting this vulnerability to us.