The Rand Core Project maintains a narrow, foundational cryptographic randomness library that is embedded across Rust applications and dependent crates, giving its small vulnerability footprint outsized significance in the supply chain despite limited direct exposure. Observed vulnerabilities cluster around buffer-size calculation errors, a parsing and allocation issue characteristic of low-level random-number generation primitives where precision in memory management is essential. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rand Core Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27378CRITICAL An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may | Feb 18, 2021 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rand Core Project.
Media articles that mention a CVE ID that affects a product developed by Rand Core Project — matched by CVE ID, not by vendor name.