rkyv has 3 CVEs on record. The busiest recent month was May 2026 with 3.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- —
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
Products
- rkyv 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
RUSTSEC-2026-0235NoneInsufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc3RUSTSEC-2026-0234NoneInsufficient archive validation can cause out-of-bounds reads in archives containing hash tables3RUSTSEC-2026-0233NoneCrafted archives can cause a use-after-free during deserialization3
rkyv vulnerabilities
CVEs affecting rkyv, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
RUSTSEC-2026-0235NoneInsufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
▾ Sunlitrkyv · rkyvvia OSV
RUSTSEC-2026-0234NoneInsufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
▾ Sunlitrkyv · rkyvvia OSV
RUSTSEC-2026-0233NoneCrafted archives can cause a use-after-free during deserialization
Crafted archives can cause a use-after-free during deserialization
▾ Sunlitrkyv · rkyvvia OSV