PT-2026-6659 · Unknown · Email-Validator

Kroemeke

·

Published

2026-01-01

·

Updated

2026-04-24

·

CVE-2026-25727

CVSS v4.0

6.8

Medium

VectorAV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions time versions 0.3.6 through 0.3.46 rust-keylime versions prior to 0.2.8+116 python-uv-build versions prior to 0.10.2 SCCache versions prior to 0.13.0
Description The time crate provides date and time handling in Rust. Versions 0.3.6 through 0.3.46 are susceptible to a denial of service attack via stack exhaustion when parsing user-provided input using the RFC 2822 format. This attack exploits formally deprecated and rarely-used features within the RFC 2822 format. The rust-keylime project includes a dependency on the 'time' crate and is therefore affected by this issue. Additionally, a heap overflow exists in SCCache 0.13.0 and earlier, potentially allowing attackers to inject persistent malware into the Rust/C++ build cache. A denial of service condition also exists in python-uv-build versions prior to 0.10.2, resulting from stack exhaustion.
Recommendations Upgrade time to version 0.3.47 or later. Upgrade rust-keylime to version 0.2.8+116 or later. Upgrade python-uv-build to version 0.10.2 or later. Upgrade SCCache to version 0.13.0 or later.

Exploit

Fix

DoS

Stack Overflow

Weakness Enumeration

Related Identifiers

AZL-76821
AZL-76994
AZL-77030
AZL-77034
AZL-77087
AZL-77091
BDU:2026-05136
CVE-2026-25727
GHSA-R6V5-FH4H-64XC
OPENSUSE-FU-2026:20453-1
OPENSUSE-SU-2026:10170-1
OPENSUSE-SU-2026:10172-1
OPENSUSE-SU-2026:10175-1
OPENSUSE-SU-2026:10179-1
OPENSUSE-SU-2026:10180-1
OPENSUSE-SU-2026:10181-1
OPENSUSE-SU-2026:10182-1
OPENSUSE-SU-2026:10184-1
OPENSUSE-SU-2026:10185-1
OPENSUSE-SU-2026:10202-1
OPENSUSE-SU-2026:10308-1
OPENSUSE-SU-2026:20245-1
OPENSUSE-SU-2026:20326-1
OPENSUSE-SU-2026:20364-1
OPENSUSE-SU-2026:20377-1
OPENSUSE-SU-2026:20380-1
OPENSUSE-SU-2026:20610-1
OPENSUSE-SU-2026:20753-1
RUSTSEC-2026-0009
SUSE-FU-2026:20990-1
SUSE-SU-2026:0452-1
SUSE-SU-2026:0453-1
SUSE-SU-2026:0470-1
SUSE-SU-2026:0505-1
SUSE-SU-2026:0506-1
SUSE-SU-2026:0514-1
SUSE-SU-2026:0582-1
SUSE-SU-2026:0620-1
SUSE-SU-2026:0806-1
SUSE-SU-2026:0816-1
SUSE-SU-2026:0819-1
SUSE-SU-2026:0860-1
SUSE-SU-2026:1361-1
SUSE-SU-2026:1599-1
SUSE-SU-2026:1750-1
SUSE-SU-2026:20526-1
SUSE-SU-2026:20534-1
SUSE-SU-2026:20575-1
SUSE-SU-2026:20661-1
SUSE-SU-2026:20684-1
SUSE-SU-2026:20723-1
SUSE-SU-2026:20744-1
SUSE-SU-2026:20748-1
SUSE-SU-2026:21275-1
SUSE-SU-2026:21377-1
SUSE-SU-2026:21794-1

Affected Products

Email-Validator