Rustcrypto maintains a focused portfolio of cryptographic libraries written in Rust, including implementations of elliptic-curve algorithms such as SM2 and RSA, that serve as building blocks across distributed systems and applications. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes centered on input validation, timing-side-channel leakage, and exception-handling gaps that are structural to cryptographic implementations where both correctness and constant-time execution are essential to security. Defenders should treat this vendor's advisories as security-critical despite its narrow scope, since cryptographic library flaws propagate to every downstream dependent; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rustcrypto over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23519CRITICAL RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior | Jan 15, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-22699HIGH RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, | Jan 10, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-22698HIGH RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, | Jan 10, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-22700HIGH RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, | Jan 10, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-21895MEDIUM The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning | Jan 8, 2026 | 5.3 | 19 | NO | NO |
CVE-2023-49092MEDIUM RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information whic | Nov 28, 2023 | 5.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rustcrypto.
Media articles that mention a CVE ID that affects a product developed by Rustcrypto — matched by CVE ID, not by vendor name.