Prost Project maintains a protocol-buffer serialization library with a narrow but strategically positioned role in Rust ecosystems, where its core exposure centers on the Prost product itself. Vulnerabilities affecting this vendor surface around memory-safety boundary conditions, including classic buffer overflows and out-of-bounds writes characteristic of serialization-layer parsing logic, with current severity and exploitation counts shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prost Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35858CRITICAL An issue was discovered in the prost crate before 0.6.1 for Rust. There is stack consumption via a crafted message, causing a denial of service (e.g., x86) or possibly remote code | Dec 31, 2020 | 9.8 | 29 | NO | NO |
CVE-2021-38192HIGH An issue was discovered in the prost-types crate before 0.8.0 for Rust. An overflow can occur during conversion from Timestamp to SystemTime. | Aug 8, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prost Project.
Media articles that mention a CVE ID that affects a product developed by Prost Project — matched by CVE ID, not by vendor name.