time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.
CVSS Details
- CVSS 4.0 Base Score: 6.8 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade amazon-efs-utilsUpgrade thunderbirdUpgrade firefox | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade librsvg2-develUpgrade belowUpgrade librsvg2-debuginfoUpgrade librsvg2-debugsourceUpgrade cargo-c-debuginfoUpgrade librsvg2-tools-debuginfoUpgrade rsvg-pixbuf-loaderUpgrade firefox-debugsourceUpgrade below-debuginfoUpgrade librsvg2Upgrade aws-nitro-tpm-toolsUpgrade mount-s3-debugsourceUpgrade rsvg-pixbuf-loader-debuginfoUpgrade librsvg2-toolsUpgrade rust-below-debugsourceUpgrade firefoxUpgrade rust-cargo-c-debugsourceUpgrade mount-s3Upgrade firefox-debuginfoUpgrade amazon-efs-utilsUpgrade cargo-cUpgrade mount-s3-debuginfo | Mar 9, 2026 | Feb 6, 2026 |
| Debian | — | Upgrade rust-time | Jul 12, 2026 | Jul 12, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 6, 2026 |
| Suse | — | Upgrade cargo-auditable | Feb 16, 2026 | Feb 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub