CVE-2026-25727: 
Rust vulnerability analysis and mitigation

Overview

CVE-2026-25727 is a stack exhaustion denial of service vulnerability in the time crate for Rust, a widely used date and time handling library. The vulnerability affects versions 0.3.6 through 0.3.46 (inclusive) and was disclosed on February 5, 2026, when maintainer jhpratt published the security advisory. When user-provided input is parsed using the RFC 2822 format, a specially crafted input exploiting deprecated comment-nesting features can trigger unbounded recursion, exhausting the call stack. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 6.8 (Medium) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is unbounded recursive parsing in the RFC 2822 comment-handling logic within time/src/parsing/combinator/rfc/rfc2822.rs. The comment and ccontent functions called each other recursively without any depth limit, classified under CWE-121 (Stack-based Buffer Overflow) due to stack exhaustion (Github Advisory). RFC 2822 permits nested comments (e.g., (comment (nested comment))) as a formally deprecated but still-valid feature; a malicious actor can craft deeply nested comment structures that cause the parser to recurse until the thread's stack is exhausted. The fix introduced a DEPTH_LIMIT constant of 32 and passes a depth counter through the recursive calls, returning None (a parse error) when the limit is reached (Patch Commit). Exploitation requires that the application passes user-controlled input to any type that parses using time::format_description::well_known::Rfc2822.

Impact

Successful exploitation causes stack exhaustion in the affected thread, resulting in a process crash or panic and a complete loss of availability for the affected service. There is no impact on confidentiality or data integrity, as the vulnerability is purely a denial of service condition. Any networked application built with the vulnerable time crate versions that accepts and parses user-supplied RFC 2822 date strings (e.g., email servers, HTTP services parsing Date: headers) is at risk of being crashed by a single malicious request (Github Advisory, GitHub Security Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of this report. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026% (8th percentile), indicating a low probability of near-term exploitation (Github Advisory). Exploitation requires that a user interact with an application that parses RFC 2822 input, and the attack relies on deprecated, rarely-used comment-nesting features, making accidental triggering extremely unlikely in practice.

Exploitation steps

  1. Identify a target application: Find a Rust application that uses the time crate (versions 0.3.6–0.3.46) and accepts user-supplied input that is parsed using the RFC 2822 date format (e.g., an email processing service, a web API that parses Date: headers).
  2. Craft a malicious RFC 2822 string: Construct an input string containing deeply nested RFC 2822 comments. RFC 2822 allows comments in parentheses, and comments can be nested. For example: ((((((...(comment)...)))))) — the nesting depth must exceed the parser's implicit recursion limit (which was unbounded before the fix).
  3. Submit the malicious input: Send the crafted string to the target application via the relevant input vector (e.g., an HTTP request field, an email Date: header, or an API parameter) that the application passes to a time RFC 2822 parser.
  4. Trigger stack exhaustion: The comment and ccontent functions in the time crate's RFC 2822 parser recurse without bound, consuming stack frames until the thread's stack is exhausted, causing a panic or process crash.
  5. Achieve denial of service: The application crashes or becomes unavailable, completing the denial of service attack (Github Advisory, Patch Commit).

Indicators of compromise

  • Logs: Application logs showing unexpected panics or thread crashes, particularly with stack overflow messages (e.g., thread 'main' has overflowed its stack) coinciding with RFC 2822 date parsing operations.
  • Process: Sudden termination of Rust application processes without a clear application-level error; repeated process restarts by a supervisor (e.g., systemd) in a short time window.
  • Network: Repeated requests to an endpoint that accepts date/time input in RFC 2822 format, especially with unusually long or deeply parenthesized values in date fields.

Mitigation and workarounds

Upgrade the time crate to version 0.3.47 or later, which introduces a recursion depth limit of 32 for RFC 2822 comment parsing; deeply nested inputs will now return a parse error instead of exhausting the stack (GitHub Release, Changelog). If an immediate upgrade is not possible, two workarounds are available: (1) limit the maximum length of user-supplied input before passing it to the parser, since stack consumption is bounded by input length; or (2) avoid the RFC 2822 format entirely by adding disallowed-types = ["time::format_description::well_known::Rfc2822"] to your clippy.toml file, which will trigger the clippy::disallowed_types lint (Github Advisory). IBM has also released a patch for affected IBM Observability with Instana (OnPrem) products (IBM Advisory).

Community reactions

The vulnerability was reported by security researcher kroemeke and remediated by jhpratt, the primary maintainer of the time crate (Github Advisory). The advisory was picked up by the RustSec advisory database (RUSTSEC-2026-0009) and propagated to multiple Linux distribution security channels including Fedora, openSUSE, SUSE, and Amazon Linux, resulting in a broad wave of downstream package updates. No significant social media controversy or major media coverage was observed, consistent with the moderate severity and limited exploitability of the issue.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rust-time: 0.3.9-1+deb12u1

Fixed

sid

rust-time: 0.3.47-1

Fixed

trixie

rust-time: 0.3.37-1+deb13u1

Fixed

Ubuntu

Unknown

devel

rust-time

Not Affected

focal (esm-apps)

rust-time

Unknown

jammy

rust-time

Unknown

jammy (esm-apps)

rust-time

Unknown

noble

rust-time

Unknown

noble (esm-apps)

rust-time

Unknown

resolute

rust-time

Unknown

resolute (esm-apps)

rust-time

Unknown

RHEL / CentOS

Affected

OpenShift

conmon-rs.src

Affected

RHEL 8

container-tools:rhel8/aardvark-dns.src

Affected

RHEL 9

firefox.src

Affected

RHEL 10

aardvark-dns.src

Affected

Source: This report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-6w6g-hm98-mhgmHIGH8.7
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-5j98-2g5x-46v6HIGH7.5
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-cjcg-cxmh-9wcrHIGH7.5
  • Rust logoRust
  • praxis-proxy
NoYesOct 02, 2026
GHSA-6f2x-v7q7-m7m5MEDIUM6.9
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-6g2r-675j-hx59LOW2.3
  • Rust logoRust
  • xxhash-rust
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management