Rust Lang maintains a programming language and its associated toolchain ecosystem, including the Cargo package manager and foundational libraries such as async runtime components, which have become prominent within systems programming and infrastructure development. The vendor's vulnerability footprint, though modest in volume, reflects the inherent exposure of a widely embedded language runtime and dependency resolver that can propagate flaws across downstream projects. Vulnerabilities affecting this vendor tend to center on memory-safety and concurrency primitives rather than the implementation flaws common to mature platforms, underscoring the language's design focus on eliminating entire classes of defects at compile time. Defenders should monitor Rust toolchain and standard-library updates alongside their downstream Rust-based applications, since remediation often requires rebuild-and-redeploy cycles across projects that depend on the standard distribution. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rust Lang over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24576CRITICAL Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking ba | Apr 9, 2024 | 10.0 | 46 | NO | NO |
CVE-2024-3566CRITICAL A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific condit | Apr 10, 2024 | 9.8 | 33 | NO | NO |
CVE-2022-24713HIGH regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted rege | Mar 8, 2022 | 7.5 | 33 | NO | NO |
CVE-2026-5222MEDIUM Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hoste | May 25, 2026 | 6.5 | 32 | NO | NO |
CVE-2021-28879CRITICAL In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. This bug can lead to a buffer overflow when a consume | Apr 11, 2021 | 9.8 | 32 | NO | NO |
CVE-2018-1000810CRITICAL The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerabil | Oct 8, 2018 | 9.8 | 32 | NO | NO |
CVE-2021-31162CRITICAL In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics. | Apr 14, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-36318CRITICAL In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use | Apr 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-29922CRITICAL library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allow | Aug 7, 2021 | 9.1 | 30 | NO | NO |
CVE-2026-5223MEDIUM Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the | May 25, 2026 | 5.3 | 29 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rust Lang.
Media articles that mention a CVE ID that affects a product developed by Rust Lang — matched by CVE ID, not by vendor name.