
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25727 is a stack exhaustion denial of service vulnerability in the time crate for Rust, a widely used date and time handling library. The vulnerability affects versions 0.3.6 through 0.3.46 (inclusive) and was disclosed on February 5, 2026, when maintainer jhpratt published the security advisory. When user-provided input is parsed using the RFC 2822 format, a specially crafted input exploiting deprecated comment-nesting features can trigger unbounded recursion, exhausting the call stack. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 6.8 (Medium) (Github Advisory, GitHub Security Advisory).
The root cause is unbounded recursive parsing in the RFC 2822 comment-handling logic within time/src/parsing/combinator/rfc/rfc2822.rs. The comment and ccontent functions called each other recursively without any depth limit, classified under CWE-121 (Stack-based Buffer Overflow) due to stack exhaustion (Github Advisory). RFC 2822 permits nested comments (e.g., (comment (nested comment))) as a formally deprecated but still-valid feature; a malicious actor can craft deeply nested comment structures that cause the parser to recurse until the thread's stack is exhausted. The fix introduced a DEPTH_LIMIT constant of 32 and passes a depth counter through the recursive calls, returning None (a parse error) when the limit is reached (Patch Commit). Exploitation requires that the application passes user-controlled input to any type that parses using time::format_description::well_known::Rfc2822.
Successful exploitation causes stack exhaustion in the affected thread, resulting in a process crash or panic and a complete loss of availability for the affected service. There is no impact on confidentiality or data integrity, as the vulnerability is purely a denial of service condition. Any networked application built with the vulnerable time crate versions that accepts and parses user-supplied RFC 2822 date strings (e.g., email servers, HTTP services parsing Date: headers) is at risk of being crashed by a single malicious request (Github Advisory, GitHub Security Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of this report. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026% (8th percentile), indicating a low probability of near-term exploitation (Github Advisory). Exploitation requires that a user interact with an application that parses RFC 2822 input, and the attack relies on deprecated, rarely-used comment-nesting features, making accidental triggering extremely unlikely in practice.
time crate (versions 0.3.6–0.3.46) and accepts user-supplied input that is parsed using the RFC 2822 date format (e.g., an email processing service, a web API that parses Date: headers).((((((...(comment)...)))))) — the nesting depth must exceed the parser's implicit recursion limit (which was unbounded before the fix).Date: header, or an API parameter) that the application passes to a time RFC 2822 parser.comment and ccontent functions in the time crate's RFC 2822 parser recurse without bound, consuming stack frames until the thread's stack is exhausted, causing a panic or process crash.thread 'main' has overflowed its stack) coinciding with RFC 2822 date parsing operations.Upgrade the time crate to version 0.3.47 or later, which introduces a recursion depth limit of 32 for RFC 2822 comment parsing; deeply nested inputs will now return a parse error instead of exhausting the stack (GitHub Release, Changelog). If an immediate upgrade is not possible, two workarounds are available: (1) limit the maximum length of user-supplied input before passing it to the parser, since stack consumption is bounded by input length; or (2) avoid the RFC 2822 format entirely by adding disallowed-types = ["time::format_description::well_known::Rfc2822"] to your clippy.toml file, which will trigger the clippy::disallowed_types lint (Github Advisory). IBM has also released a patch for affected IBM Observability with Instana (OnPrem) products (IBM Advisory).
The vulnerability was reported by security researcher kroemeke and remediated by jhpratt, the primary maintainer of the time crate (Github Advisory). The advisory was picked up by the RustSec advisory database (RUSTSEC-2026-0009) and propagated to multiple Linux distribution security channels including Fedora, openSUSE, SUSE, and Amazon Linux, resulting in a broad wave of downstream package updates. No significant social media controversy or major media coverage was observed, consistent with the moderate severity and limited exploitability of the issue.
Fix availability across major Linux distributions and their releases.
bookworm
rust-time: 0.3.9-1+deb12u1
sid
rust-time: 0.3.47-1
trixie
rust-time: 0.3.37-1+deb13u1
devel
rust-time
focal (esm-apps)
rust-time
jammy
rust-time
jammy (esm-apps)
rust-time
noble
rust-time
noble (esm-apps)
rust-time
resolute
rust-time
resolute (esm-apps)
rust-time
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."