Time-Rs Time vulnerabilities
2 known vulnerabilities affecting time-rs/time.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-25727MEDIUMCVSS 6.8v>= 0.3.6, < 0.3.472026-02-06
CVE-2026-25727 [MEDIUM] CWE-121 CVE-2026-25727: time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input
time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner
cvelistv5nvd
CVE-2020-26235MEDIUMCVSS 5.3v>= 0.2.7, <0.2.232020-11-24
CVE-2020-26235 [MEDIUM] CWE-476 CVE-2020-26235: In Rust time crate from version 0.2.7 and before version 0.2.23, unix-like operating systems may seg
In Rust time crate from version 0.2.7 and before version 0.2.23, unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires the user to set any environment variable in a different thread than the affected functions. The affected functions are time::UtcOffset::local_offset_at, time::UtcOf
cvelistv5nvd