Crossbeam is a Rust concurrency library providing synchronization primitives and concurrent data structures widely embedded in systems software; its vulnerability footprint, though limited, centers on memory-safety and synchronization issues including race conditions, double frees, and buffer boundary violations that reflect the low-level nature of synchronization code. Treat this as a niche vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Crossbeam Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15254CRITICAL Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capac | Oct 16, 2020 | 9.8 | 31 | NO | NO |
CVE-2021-32810CRITICAL crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition i | Aug 2, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-20996CRITICAL An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling. | Aug 26, 2019 | 9.8 | 28 | NO | NO |
CVE-2022-23639HIGH crossbeam-utils provides atomics, synchronization primitives, scoped threads, and other utilities for concurrent programming in Rust. crossbeam-utils prior to version 0.8.7 incorre | Feb 15, 2022 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Crossbeam Project.
Media articles that mention a CVE ID that affects a product developed by Crossbeam Project — matched by CVE ID, not by vendor name.