In Rust
Last updated: Sep 30, 2026
A transitive dependency (also called an indirect dependency) is a package that your project does not use directly. One of your direct or intermediate dependencies needs it.
Try the strategies below in this sequence. Move to the next strategy only if the previous one does not correct the problem.
Identify the dependency chain
For strategies 2 and 3, find the direct or intermediate dependency that pulls in the vulnerable crate:
cargo tree -i <crate>The -i flag inverts the tree.
The crate that you named is at the root.
The tree branches out to the crates that depend on it.
To learn if the same crate is in the tree at more than one version,
run:
cargo tree -dStrategy 1: Update the transitive dependency
The first and simplest method is to update the vulnerable crate directly.
cargo update -p <crate>To select a version that is not the newest permitted one, name it:
cargo update -p <crate> --precise <safe-version>This works when the version requirements in the tree
let Cargo select a release with the security patch.
If a direct or intermediate dependency needs a range
that excludes the patched release,
cargo update -p <crate> does not move it.
Strategy 2: Update the direct or intermediate dependency
If strategy 1 did not update the transitive crate,
a direct or intermediate dependency probably constrains its version.
Update the version of the direct dependency in your Cargo.toml:
[dependencies]
direct-or-intermediate-crate = "<new-version>"This can pull in a newer version of the transitive crate with the security fix. But the direct dependency can be at its latest version and continue to use the vulnerable crate. If it does, this strategy also does not correct the problem.
Strategy 3: Patch the dependency
Cargo has no version override.
The only method to replace a crate across the full graph is [patch].
It redirects the crate to a different source,
not to a different version of the registry.
You must supply the fixed code. Fork the crate. Apply the patch on your fork. Then point the entry at it.
[patch.crates-io]
<crate> = { git = "https://github.com/<you>/<crate>", branch = "<branch>" }The patch is transitive and applies to the full dependency graph. But you can declare it only in the manifest at the root of the workspace.
The patched source must stay SemVer compatible with what the graph needs. In
Cargo, the leftmost non-zero component sets the compatibility: 0.30 and
0.31 are not compatible with each other, the same as 1.0 and 2.0. If you
patch across that boundary, Cargo does not apply the patch. You then get two
copies of the crate, and not one.
Strategy 4: Wait for maintainers, or drop the crate
If no patch works, the usual path is to wait for the upstream maintainers. Two releases are necessary:
- The maintainers of the vulnerable crate publish a patched version.
- The maintainers of the direct or intermediate dependency release a new version that adopts it.
Rust also has a problem with no equivalent in other ecosystems. A large share of RUSTSEC advisories report a crate as unmaintained. Those frequently have no patched version in the full tree. No strategy corrects them, because there is no version to update to.
You have two options. The first is to remove the dependency. Frequently, you can do this when you disable the default features that pull it in. The second is to accept the risk through your vulnerability management workflow.
In Kotlin
Learn the recommended strategies to remediate SCA vulnerabilities found in transitive Kotlin Gradle dependencies, from raising a version constraint to forcing a resolution strategy.
Introduction to Sorts
Learn about Sorts, the Fluid Attacks AI tool for prioritizing files in your software according to their likelihood of having vulnerabilities.