RUSTSEC-2026-0009: Denial of Service via Stack Exhaustion
| Details | |
| --- | --- |
| Package | `time` |
| Version | `0.3.44` |
| URL | https://github.com/time-rs/time/blob/main/CHANGELOG.md#0347-2026-02-05 |
| Patched Versions | >=0.3.47 |
| Unaffected Versions | <0.3.6 |
| Aliases | [CVE-2026-25727](https://nvd.nist.gov/vuln/detail/CVE-2026-25727), [GHSA-r6v5-fh4h-64xc](https://github.com/advisories/GHSA-r6v5-fh4h-64xc) |
## Impact
When user-provided input is provided to any type that parses with the RFC 2822 format, a denial of
service attack via stack exhaustion is possible. The attack relies on formally deprecated and
rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary,
non-malicious input will never encounter this scenario.
## Patches
A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned
rather than exhausting the stack.
## Workarounds
Limiting the length of user input is the simplest way to avoid stack exhaustion, as the amount of
the stack consumed would be at most a factor of the length of the input.
关闭于 2026-02-07 0 条评论