CVE-2026-25727Patch(time_project / time)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch time_project time systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • time

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 3 mentions (2026-02-22); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Products
time

Deep dive

Activity timeline11 mentions / 8d
01223Mentions · 2026-02-06: 1Mentions · 2026-02-10: 2Mentions · 2026-02-12: 1Mentions · 2026-02-22: 3Mentions · 2026-02-25: 1Mentions · 2026-03-09: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-22: 2Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-22: 3Technical Details · 2026-02-25: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 102-0602-1002-1202-2202-2503-0903-1103-13
Signal classification2 categories
Patch
763.6%
Disclosure
436.4%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-061
Disclosure1
2026-02-102
Patch2
2026-02-121
Disclosure1
2026-02-223
Disclosure1Patch2
2026-02-251
Patch1
2026-03-091
Patch1
2026-03-111
Disclosure1
2026-03-131
Patch1
Full discourse11 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Urgent Security Update for Fedora Users! 🚨 Critical vulnerabilities CVE-2026-25537 & CVE-2026-25727 affect tbtools and multiple Rust applications in #Fedora 43. Read more: 👉 https://tinyurl.com/yyantywz #Security https://t.co/pFiZNCNmK1

    Post summary

    The tweet alerts Fedora 43 users to critical vulnerabilities in tbtools and Rust applications, urging immediate action, but provides no technical exploitation details or patch specifics.

    0001053
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25727 time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a de… https://www.cve.org/CVERecord?id=CVE-2026-25727

    Post summary

    The text reports a vulnerability in Rust’s time crate, affecting versions 0.3.6 through 0.3.46, where user‑provided RFC 2822 date‑time input can trigger an issue; the CVE is documented on cve.org.

    00010165
    56.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security release for #Fedora 43: Taskwarrior 3.4.2 is out. It fixes a stack exhaustion DoS (CVE-2026-25727) and multiple AWS-LC crypto vulns. Read more: 👉 https://tinyurl.com/536zwx9t #Security https://t.co/5JyEQXuIYs

    Post summary

    This tweet announces the release of Fedora 43’s security update, which includes Taskwarrior 3.4.2 that patches the stack exhaustion DoS CVE-2026-25727 and addresses additional AWS‑LC crypto vulnerabilities.

    0000040
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Critical: python-maturin on openSUSE Leap 15.6 has a high-severity stack exhaustion flaw (CVE-2026-25727, CVSS 8.7). Attacker can crash apps by sending a malicious RFC 2822 date string. Read more: 👉 https://tinyurl.com/erawtymj #openSUSE #Security https://t.co/JRBrUTbfw2

    Post summary

    A high‑severity stack exhaustion vulnerability (CVE‑2026‑25727) has been disclosed for python‑maturin on openSUSE Leap 15.6, triggered by malicious RFC 2822 date strings and rated CVSS 8.7.

    0000084
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads-up, self-hosters and sysadmins! 🚨 Just published a deep dive on the new #openSUSE Tumbleweed security update for virtiofsd (CVE-2026-25727). Read more: 👉 https://tinyurl.com/3zcuksue #Security https://t.co/D02UkXlDpf

    Post summary

    The tweet promotes a deep dive article that discusses the openSUSE Tumbleweed security update addressing CVE‑2026‑25727 in virtiofsd.

    0000056
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT: #SUSE Linux 15 SP7 snpguest update (2026-0620-1) is out! Patches critical CVE-2026-25727 (stack exhaustion) & CVE-2025-3416 (Use-After-Free). Update to v0.10.0 NOW to secure your SEV-SNP workloads. Read more:👉 https://tinyurl.com/27pwz3pr #Security https://t.co/qgXRCAlSes

    Post summary

    SUSE Linux 15 SP7 snpguest update v0.10.0 has been released to patch CVE-2026-25727 (stack exhaustion) and CVE-2025-3416 (Use-After-Free) for SEV-SNP workloads.

    0000070
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical Security Update for #Fedora 42 Users A new update is available for python-uv-build (version 0.10.2) that addresses a significant Denial of Service vulnerability (CVE-2026-25727). Read more: 👉 https://tinyurl.com/58czbect #Security https://t.co/4Qqr0ZkmnW

    Post summary

    Fedora 42 users are advised to install the new python-uv-build 0.10.2 update to mitigate a Denial of Service vulnerability (CVE-2026-25727).

    0000071
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    The latest uv update for #Fedora 42 (0.10.2) is a mandatory security patch. It fixes CVE-2026-25727, a stack exhaustion DoS in python-uv-build. Read mroe: 👉 https://tinyurl.com/2p9sryzj #Security https://t.co/ISF7RxFPO3

    Post summary

    The tweet announces a mandatory security patch for Fedora 42 that addresses CVE‑2026‑25727, a stack exhaustion DoS vulnerability in python‑uv‑build.

    0000067
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Is your #Fedora 42 build environment secure? 🛡️ A new high-severity vulnerability (CVE-2026-25727) targets python-uv-build, risking total system crashes via stack exhaustion. 🐍💥 Read more: 👉 https://tinyurl.com/2uh6ha34 #Security https://t.co/DCw5MYZqSd

    Post summary

    A new high‑severity CVE‑2026‑25727 affecting python‑uv‑build is disclosed, potentially causing system crashes via stack exhaustion, but no PoC, exploit, or patch details are provided.

    0000071
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 ALERT: CVE-2026-25727 drops with an 8.2 CVSS. #OpenSUSE Leap 15.5/15.6 + SCCache 0.13.0 = Heap overflow in distributed compilation. Attackers inject persistent malware into your #Rust/#C++ build cache. Read more: 👉 https://tinyurl.com/2xkdy69w #Security https://t.co/24FR2voqxl

    Post summary

    CVE‑2026‑25727 is disclosed as a heap overflow in SCCache on OpenSUSE Leap 15.5/15.6 with a high CVSS score, but no PoC, exploit, or patch details are provided.

    0000063
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 CRITICAL: #Fedora 43 #Security Advisory Update 🚨 CVE-2026-25537 (auth bypass) + CVE-2026-25727 (stack exhaustion) now patched. Affects tuigreet, rustup, keylime-agent-rust + 6 other packages. This is a SOFTWARE SUPPLY CHAIN incident. Read more: 👉 https://tinyurl.com/4ky4w8mt https://t.co/lhce38Lp3n

    Post summary

    Fedora 43 has issued a critical security advisory indicating that CVE-2026-25537 (auth bypass) and CVE-2026-25727 (stack exhaustion) are now patched, and the incident is classified as a software supply chain event.

    0000043
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptime_projecttime-rust-

Explore more