rsa
Activity
- Latest release
- 4mo ago
- Total releases
- 64
- Cadence
- ~17 days
- Last 12 months
- 11
Details
- License
- MIT OR Apache-2.0
- First release
- Jul 24, 2018
| Version | Released | |
|---|---|---|
0.10.0-rc.18
unknown
|
0.10.0-rc.18
unknown
Dependencies (28)
+ 20 more |
|
0.10.0-rc.17
unknown
|
0.10.0-rc.17
unknown
Dependencies (28)
+ 20 more |
|
0.10.0-rc.16
unknown
|
0.10.0-rc.16
unknown
Dependencies (28)
+ 20 more |
|
0.10.0-rc.15
unknown
|
0.10.0-rc.15
unknown
Dependencies (28)
+ 20 more |
|
0.10.0-rc.14
unknown
|
0.10.0-rc.14
unknown
Dependencies (28)
+ 20 more |
|
0.10.0-rc.13
unknown
|
0.10.0-rc.13
unknown
Dependencies (28)
+ 20 more |
|
0.10.0-rc.12
unknown
|
0.10.0-rc.12
unknown
Dependencies (28)
+ 20 more |
|
0.9.10
unknown
|
0.9.10
unknown
Dependencies (26)
+ 18 more |
|
0.10.0-rc.11
unknown
|
0.10.0-rc.11
unknown
Dependencies (28)
+ 20 more |
|
0.9.9
unknown
1 CVE
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.9
unknown
Dependencies (26)
+ 18 more |
|
0.10.0-rc.10
unknown
|
0.10.0-rc.10
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.9
unknown
|
0.10.0-rc.9
unknown
Dependencies (30)
+ 22 more |
|
0.10.0-rc.8
unknown
|
0.10.0-rc.8
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.7
unknown
|
0.10.0-rc.7
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.6
unknown
|
0.10.0-rc.6
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.5
unknown
|
0.10.0-rc.5
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.4
unknown
|
0.10.0-rc.4
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.3
unknown
|
0.10.0-rc.3
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.2
unknown
|
0.10.0-rc.2
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.1
unknown
|
0.10.0-rc.1
unknown
Dependencies (29)
+ 21 more |
|
0.10.0-rc.0
unknown
|
0.10.0-rc.0
unknown
Dependencies (29)
+ 21 more |
|
0.9.8
unknown
1 CVE
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.8
unknown
Dependencies (26)
+ 18 more |
|
0.10.0-pre.4
unknown
|
0.10.0-pre.4
unknown
Dependencies (26)
+ 18 more |
|
0.9.7
unknown
1 CVE
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.7
unknown
Dependencies (26)
+ 18 more |
|
0.10.0-pre.3
unknown
|
0.10.0-pre.3
unknown
Dependencies (27)
+ 19 more |
|
0.10.0-pre.2
unknown
|
0.10.0-pre.2
unknown
Dependencies (27)
+ 19 more |
|
0.10.0-pre.1
unknown
|
0.10.0-pre.1
unknown
Dependencies (26)
+ 18 more |
|
0.10.0-pre.0
unknown
|
0.10.0-pre.0
unknown
Dependencies (26)
+ 18 more |
|
0.9.6
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.6
unknown
Dependencies (26)
+ 18 more |
|
0.9.5
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.5
unknown
Dependencies (26)
+ 18 more |
|
0.9.4
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.4
unknown
Dependencies (26)
+ 18 more |
|
0.9.3
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.3
unknown
Dependencies (26)
+ 18 more |
|
0.9.2
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.2
unknown
Dependencies (28)
+ 20 more |
|
0.9.1
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.1
unknown
Dependencies (27)
+ 19 more |
|
0.9.0
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.0
unknown
Dependencies (26)
+ 18 more |
|
0.9.0-rc.0
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.0-rc.0
unknown
Dependencies (26)
+ 18 more |
|
0.9.0-pre.2
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.0-pre.2
unknown
Dependencies (26)
+ 18 more |
|
0.9.0-pre.1
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.0-pre.1
unknown
Dependencies (26)
+ 18 more |
|
0.9.0-pre.0
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.9.0-pre.0
unknown
Dependencies (24)
+ 16 more |
|
0.8.2
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.8.2
unknown
Dependencies (24)
+ 16 more |
|
0.8.1
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.8.1
unknown
Dependencies (24)
+ 16 more |
|
0.8.0
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.8.0
unknown
Dependencies (23)
+ 15 more |
|
0.8.0-rc.0
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.8.0-rc.0
unknown
Dependencies (23)
+ 15 more |
|
0.8.0-pre.0
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.8.0-pre.0
unknown
Dependencies (23)
+ 15 more |
|
0.7.2
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.2
unknown
Dependencies (24)
+ 16 more |
|
0.7.1
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.1
unknown
Dependencies (24)
+ 16 more |
|
0.7.0
unknown
yanked
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.0
unknown
yanked
Dependencies (24)
+ 16 more |
|
0.7.0-rc.1
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.0-rc.1
unknown
Dependencies (24)
+ 16 more |
|
0.7.0-rc.0
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.0-rc.0
unknown
Dependencies (24)
+ 16 more |
|
0.7.0-pre
unknown
2 CVEs
CVE-2026-21895
GHSA-9c48-w39g-hm26
Jan 06, 2026
rsa crate has potential panic on a prime being equal to 1
Low
Network
Low
None
None
When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG. Fixed in
0.9.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-49092
GHSA-c38w-74pg-36hr
GHSA-4grx-2x9w-596c
RUSTSEC-2023-0071
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactDue to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key. PatchesNo patch is yet available, however work is underway to migrate to a fully constant-time implementation. WorkaroundsThe only currently available workaround is to avoid using the ReferencesThis vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.0-pre
unknown
Dependencies (23)
+ 15 more |