Vulnerability DatabaseRUSTSEC-2020-0021

RUSTSEC-2020-0021
Rust vulnerability analysis and mitigation

Overview

A memory safety vulnerability was discovered in the rio crate through 2020-05-11 for Rust, identified as RUSTSEC-2020-0021 (CVE-2020-35876). The vulnerability allows for struct leakage that could potentially expose sensitive information, lead to use-after-free conditions, or cause data races (NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 Base Score of 9.8 CRITICAL with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Under CVSS v2.0, it received a Base Score of 7.5 HIGH with the vector (AV:N/AC:L/Au:N/C:P/I:P/A:P). The vulnerability is associated with CWE-416 (Use After Free) and CWE-772 (Missing Release of Resource after Effective Lifetime) (NVD).

Impact

The vulnerability can lead to multiple severe consequences including exposure of sensitive information through struct leakage, potential use-after-free conditions, and data races. These impacts could compromise the security and stability of affected systems (NVD).

Exploitability

The vulnerability is considered highly exploitable as indicated by its CVSS metrics, requiring no privileges (PR:N) and no user interaction (UI:N) for exploitation. It can be accessed over the network (AV:N) with low attack complexity (AC:L) (NVD).

Mitigation and workarounds

The affected versions include all versions of the rio crate through 2020-05-11. Users should update to a patched version of the crate when available (NVD).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-mc9m-6fm9-pghcMEDIUM6.9
  • Python logoPython
  • zoo-kcl
NoYesAug 20, 2026
GHSA-jgvr-6x5w-hx5wMEDIUM6.9
  • Python logoPython
  • zoo-kcl
NoYesAug 20, 2026
CVE-2026-54136MEDIUM5.1
  • Rust logoRust
  • windmill-api
NoYesAug 20, 2026
RUSTSEC-2026-0266NONEN/A
  • Rust logoRust
  • internment
NoYesAug 20, 2026
RUSTSEC-2026-0265NONEN/A
  • Rust logoRust
  • proc-macro1
NoNoAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management