Servo maintains a narrow but critically deployed set of components, including the smallvec utility library and IDNA domain-name handling, that are embedded across memory-safe and web-facing codebases. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, with a notable emphasis on memory-safety failures such as double-free and out-of-bounds-write conditions alongside web-layer issues like cross-site request forgery and improper input validation. Defenders should monitor this vendor's advisories closely for its role in the Rust ecosystem and web infrastructure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Servo over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15554CRITICAL An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity. | Aug 26, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-15551CRITICAL An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity. | Aug 26, 2019 | 9.8 | 30 | NO | NO |
CVE-2021-25900CRITICAL An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many. | Jan 26, 2021 | 9.8 | 28 | NO | NO |
CVE-2018-20991CRITICAL An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free. | Aug 26, 2019 | 9.8 | 28 | NO | NO |
CVE-2018-25023HIGH An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type. | Dec 27, 2021 | 7.5 | 25 | NO | NO |
CVE-2024-12224HIGH Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat a | May 30, 2025 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Servo.
Media articles that mention a CVE ID that affects a product developed by Servo — matched by CVE ID, not by vendor name.