Salvo is a niche web application framework with a focused vulnerability footprint centered on its core product, characterized by recurring input-handling and resource-management weaknesses including cross-site scripting, path traversal, and unthrottled resource allocation. These patterns reflect the exposure surface typical of web frameworks where input validation and path sanitization are critical to application security. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Salvo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22257HIGH Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may pot | Jan 8, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-33242HIGH Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows a | Mar 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-33241HIGH Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits | Mar 24, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-22256HIGH Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its in | Jan 8, 2026 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Salvo.
Media articles that mention a CVE ID that affects a product developed by Salvo — matched by CVE ID, not by vendor name.