Time Project's vulnerability footprint centers on its time-synchronization software, a narrowly scoped but foundational component in network infrastructure where precision timekeeping is critical. The observed weakness classes—NULL pointer dereferences and stack-based buffer overflows—reflect the memory-safety challenges inherent to low-level protocol parsing and system time-management code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Time Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25727MEDIUM time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of servic | Feb 6, 2026 | 6.5 | 26 | NO | NO |
CVE-2020-26235MEDIUM In Rust time crate from version 0.2.7 and before version 0.2.23, unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This re | Nov 24, 2020 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Time Project.
Media articles that mention a CVE ID that affects a product developed by Time Project — matched by CVE ID, not by vendor name.