rojo vulnerabilities
CVEs whose affected-version data names the rojo package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-97875High· 8.1Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding
Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local progr…
▾ Twilightrojo-rbx · rojovia NVD
RUSTSEC-2026-0279High· 8.1Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
▾ Twilightrojo · rojovia OSV