CVE Tools

Rust-lang

20 CVEs tracked since 2020. Since Dec 2020, none of them reached CISA KEV.

Rust-lang CVEs per month

Dec 2020 to Apr 2021. Point at a month, or focus the strip and use the arrow keys.
Rust-lang CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-1260
2021-0120
2021-02null or fewer
2021-03null or fewer
2021-04120

Products

The products that kept showing up in Rust-lang's monthly top three, with their CVEs summed over those months.

  1. Rust121 month
  2. Future-utils21 month
  3. Futures-task21 month
  4. Async-h111 month
  5. Mdbook11 month
  6. Socket211 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Rust-lang.

  1. CVE-2026-5223Crates in third party registries can override the cached source of other crates5.3
  2. CVE-2026-5222Cargo can be coerced to share credentials between registries6.5
  3. CVE-2024-43402Rust OS Command Injection/Argument Injection vulnerability8.1
  4. CVE-2024-3566Command injection vulnerability in programing languages on Microsoft Windows operating system.9.8
  5. CVE-2024-24576Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows10.0
  6. CVE-2023-40030Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports6.1
  7. CVE-2023-38497Cargo not respecting umask when extracting crate archives7.9
  8. CVE-2022-46176Cargo did not verify SSH host keys5.3
  9. CVE-2022-36113Extracting malicious crates can corrupt arbitrary files4.6
  10. CVE-2022-36114Extracting malicious crates can fill the file system4.8
  11. CVE-2022-24713Regular expression denial of service in Rust's regex crate7.5
  12. CVE-2022-21658Race condition in std::fs::remove_dir_all in rustlang7.3
  13. CVE-2021-29922library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to by...9.1
  14. CVE-2017-20004In the standard library in Rust before 1.19.0, there is a synchronization problem in the MutexGuard object. MutexGuards can be used across threads with any types, allowing for memory safety issues ...5.9
  15. CVE-2020-36323In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes...8.2

The record

Peak rank
#50 in Apr 2021
Busiest month shown
Apr 2021, 12 CVEs
Months with a KEV entry
0 since Dec 2020
Monthly snapshots
3 since 2020
Rust-lang's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store