The Serde Cbor Project maintains a serialization library for CBOR (Concise Binary Object Representation) encoding and decoding, a niche component used in systems requiring compact binary data interchange. Its observed vulnerability profile centers on the memory-safety demands of parsing untrusted binary data, with documented exposure in out-of-bounds write conditions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Serde Cbor Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25001HIGH An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumption via nested semantic tags. | Dec 31, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Serde Cbor Project.
Media articles that mention a CVE ID that affects a product developed by Serde Cbor Project — matched by CVE ID, not by vendor name.