The Evm Project's vulnerability profile is concentrated in the Evm product itself, a narrowly scoped component that carries elevated prominence in its operational domain. Observed weaknesses center on control-flow correctness, resource-management limits, exception handling, and memory-boundary conditions, reflecting the challenges of robust virtual-machine implementation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evm Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41153CRITICAL The evm crate is a pure Rust implementation of Ethereum Virtual Machine. In `evm` crate `< 0.31.0`, `JUMPI` opcode's condition is checked after the destination validity check. Howe | Oct 18, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-39354HIGH SputnikVM, also called evm, is a Rust implementation of Ethereum Virtual Machine. A custom stateful precompile can use the `is_static` parameter to determine if the call is execute | Oct 25, 2022 | 7.5 | 24 | NO | NO |
CVE-2024-21629HIGH Rust EVM is an Ethereum Virtual Machine interpreter. In `rust-evm`, a feature called `record_external_operation` was introduced, allowing library users to record custom gas changes | Jan 2, 2024 | 7.5 | 21 | NO | NO |
CVE-2021-29511MEDIUM evm is a pure Rust implementation of Ethereum Virtual Machine. Prior to the patch, when executing specific EVM opcodes related to memory operations that use `evm_core::Memory::copy | May 12, 2021 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evm Project.
Media articles that mention a CVE ID that affects a product developed by Evm Project — matched by CVE ID, not by vendor name.