Nanorand Project maintains a cryptographic random-number generation library with a narrow product scope but presence across security-sensitive applications that depend on quality entropy. The observed vulnerability signals center on numeric-type handling and randomness-generation mechanisms, reflecting the precision and statistical-property demands of a cryptographic library. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nanorand Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45705CRITICAL An issue was discovered in the nanorand crate before 0.6.1 for Rust. There can be multiple mutable references to the same object because the TlsWyRand Deref implementation derefere | Dec 27, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-35926CRITICAL An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishand | Dec 31, 2020 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nanorand Project.
Media articles that mention a CVE ID that affects a product developed by Nanorand Project — matched by CVE ID, not by vendor name.