Vulnerability DatabaseRUSTSEC-2024-0395

RUSTSEC-2024-0395
Rust vulnerability analysis and mitigation

Overview

RUSTSEC-2024-0395 affects the chrono-english Rust crate, which is a library for parsing human-readable date/time expressions. The vulnerability stems from the maintainer becoming unresponsive, leading to unresolved compatibility issues with newer versions of the chrono dependency. The issue was first reported on March 31, 2024, when users encountered compilation errors with recent chrono versions (GitHub Issue).

Technical details

The technical issue manifests as a compilation error with the trait bound Tz: Copy not being satisfied, specifically affecting the functionality in the types.rs file. This occurs when using chrono 0.4.37 and chrono-tz 0.8.6, indicating a breaking change in the chrono dependency that wasn't addressed in chrono-english (GitHub Issue).

Impact

The vulnerability impacts projects depending on chrono-english, preventing them from upgrading to newer versions of chrono. This creates a dependency lock situation where projects either have to stay on older versions of chrono or find alternative solutions (GitHub Issue).

Mitigation and workarounds

Users are recommended to switch to alternative libraries, specifically the interim crate (https://github.com/conradludgate/interim), which serves as a drop-in replacement with the same API surface and is actively maintained (GitHub Issue).

Community reactions

The community has actively discussed the issue on GitHub, with developers expressing concern about the maintenance status of the library. Several attempts were made to fix the issue through pull requests, but due to the maintainer's unresponsiveness, the community has begun migrating to alternative solutions (GitHub Issue).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-53530HIGH8.7
  • Rust logoRust
  • ratex-parser
NoYesAug 21, 2026
CVE-2026-53531MEDIUM6.9
  • Rust logoRust
  • ratex-parser
NoYesAug 21, 2026
GHSA-mc9m-6fm9-pghcMEDIUM6.9
  • Python logoPython
  • zoo-kcl
NoYesAug 20, 2026
GHSA-jgvr-6x5w-hx5wMEDIUM6.9
  • Python logoPython
  • kcl-lib
NoYesAug 20, 2026
CVE-2026-54136MEDIUM5.1
  • Rust logoRust
  • windmill-api
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management