RustCrypto records
7 published records for vendor rustcrypto.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-208 Observable Timing Discrepancy1
- CWE-331 Insufficient Entropy1
- CWE-385 Covert Timing Channel1
- CWE-703 Improper Check or Handling of Exceptional Conditions1
- CWE-758 Reliance on Undefined, Unspecified, or Implementation-Defined Behavior1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2026-23519No exploit | RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnzrustcrypto · cmov · CWE-208 | High8.9 | — | 0.6% | Jan 15, 2026 |
34Monitor | CVE-2026-22698No exploit | RustCrypto SM2-PKE has 32-bit Biased Nonce Vulnerabilityrustcrypto · sm2 elliptic curve · CWE-331 | High8.7 | — | 0.3% | Jan 10, 2026 |
30Monitor | CVE-2026-22699No exploit | RustCrypto SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()rustcrypto · sm2 elliptic curve · CWE-20 | High7.5 | — | 0.4% | Jan 10, 2026 |
30Monitor | CVE-2026-22700No exploit | RustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKErustcrypto · sm2 elliptic curve · CWE-20 | High7.5 | — | 0.3% | Jan 10, 2026 |
23Monitor | CVE-2023-49092No exploit | RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannelsrustcrypto · rsa · CWE-385 | Medium5.9 | — | 0.6% | Nov 28, 2023 |
10Monitor | CVE-2026-21895No exploit | rsa crate has potential panic on a prime being equal to 1rustcrypto · rsa · CWE-703 | Low2.7 | — | 0.5% | Jan 8, 2026 |
8Monitor | CVE-2026-50185No exploit | RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are setrustcrypto · cmov · CWE-758 | Low2.0 | — | 0.2% | Jul 17, 2026 |
- CVE-2026-2351935Monitor
RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz
HighCVSS 8.9No exploitEPSS 1%rustcrypto · cmovJan 15, 2026
- CVE-2026-2269834Monitor
RustCrypto SM2-PKE has 32-bit Biased Nonce Vulnerability
HighCVSS 8.7No exploitEPSS 0%rustcrypto · sm2 elliptic curveJan 10, 2026
- CVE-2026-2269930Monitor
RustCrypto SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()
HighCVSS 7.5No exploitEPSS 0%rustcrypto · sm2 elliptic curveJan 10, 2026
- CVE-2026-2270030Monitor
RustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKE
HighCVSS 7.5No exploitEPSS 0%rustcrypto · sm2 elliptic curveJan 10, 2026
- CVE-2023-4909223Monitor
RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels
MediumCVSS 5.9No exploitEPSS 1%rustcrypto · rsaNov 28, 2023
- CVE-2026-2189510Monitor
rsa crate has potential panic on a prime being equal to 1
LowCVSS 2.7No exploitEPSS 0%rustcrypto · rsaJan 8, 2026
- CVE-2026-501858Monitor
RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set
LowCVSS 2.0No exploitEPSS 0%rustcrypto · cmovJul 17, 2026