FlawAtlas
Search the atlas
CVE-2026-25727 Not scored

time affected by a stack exhaustion denial of service attack

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.

Exploit probability 0.3%
Published February 6, 2026
Required by Not available
Last source change July 16, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

40 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related CGA-CQ26-69JV-QP5C
related OPENSUSE-FU-2026:20453-1
related OPENSUSE-SU-2026:10170-1
related OPENSUSE-SU-2026:10172-1
related OPENSUSE-SU-2026:10175-1
related OPENSUSE-SU-2026:10179-1
related OPENSUSE-SU-2026:10180-1
related OPENSUSE-SU-2026:10181-1
related OPENSUSE-SU-2026:10182-1
related OPENSUSE-SU-2026:10184-1
related OPENSUSE-SU-2026:10185-1
related OPENSUSE-SU-2026:10202-1
related OPENSUSE-SU-2026:10308-1
related OPENSUSE-SU-2026:20245-1
related OPENSUSE-SU-2026:20326-1
related OPENSUSE-SU-2026:20364-1
related OPENSUSE-SU-2026:20377-1
related OPENSUSE-SU-2026:20380-1
related OPENSUSE-SU-2026:20610-1
related OPENSUSE-SU-2026:20753-1
related SUSE-FU-2026:20990-1
related SUSE-SU-2026:0452-1
related SUSE-SU-2026:0453-1
related SUSE-SU-2026:0470-1
related SUSE-SU-2026:0505-1
related SUSE-SU-2026:0506-1
related SUSE-SU-2026:0514-1
related SUSE-SU-2026:0582-1
related SUSE-SU-2026:0620-1
related SUSE-SU-2026:0806-1
related SUSE-SU-2026:0816-1
related SUSE-SU-2026:0819-1
related SUSE-SU-2026:0860-1
related SUSE-SU-2026:1361-1
related SUSE-SU-2026:1599-1
related SUSE-SU-2026:1750-1
related SUSE-SU-2026:20526-1
related SUSE-SU-2026:20534-1
related SUSE-SU-2026:20575-1
related SUSE-SU-2026:20661-1
related SUSE-SU-2026:20684-1
related SUSE-SU-2026:20723-1
related SUSE-SU-2026:20744-1
related SUSE-SU-2026:20748-1
related SUSE-SU-2026:21275-1
related SUSE-SU-2026:21377-1
related SUSE-SU-2026:21794-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-25727

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.

View original source

05 / REFERENCES

Further evidence