rand vulnerabilities
CVEs whose affected-version data names the rand package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
RUSTSEC-2026-0097NoneRand is unsound with a custom logger using `rand::rng()`
Rand is unsound with a custom logger using `rand::rng()`
▾ Sunlitrand · randvia OSV
CVE-2020-25576Critical· 9.8An issue was discovered in the rand_core crate before 0.4.2 for Rust
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
▾ Midnightrust-random · randEPSS 1.6%via NVD