Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Servo

First CVE: Aug 26, 2019Active for: 7 yearsTotal CVEs: 6

Servo maintains a narrow but critically deployed set of components, including the smallvec utility library and IDNA domain-name handling, that are embedded across memory-safe and web-facing codebases. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, with a notable emphasis on memory-safety failures such as double-free and out-of-bounds-write conditions alongside web-layer issues like cross-site request forgery and improper input validation. Defenders should monitor this vendor's advisories closely for its role in the Rust ecosystem and web infrastructure; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
9.3
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Servo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2019
6 years ago
Most Recent CVE
May 30, 2025
420 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-15554CRITICAL
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity.
Aug 26, 20199.831NONO
CVE-2019-15551CRITICAL
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity.
Aug 26, 20199.830NONO
CVE-2021-25900CRITICAL
An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.
Jan 26, 20219.828NONO
CVE-2018-20991CRITICAL
An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free.
Aug 26, 20199.828NONO
CVE-2018-25023HIGH
An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.
Dec 27, 20217.525NONO
CVE-2024-12224HIGH
Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat a
May 30, 20258.824NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Servo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Servo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Servo's Products

View all 2 CNAs →

Top CWEs