GothenburgBitFactory / GothenburgBitFactory/taskwarrior

RUSTSEC-2026-0009: Denial of Service via Stack Exhaustion

Open
#4,053 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C++
Stars
6.1k
Forks
423
Avg merge
1d 19h
Merged PRs (30d)
11

Description

> Denial of Service via Stack Exhaustion

| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `time` |
| Version | `0.3.45` |
| URL | [https://github.com/time-rs/time/blob/main/CHANGELOG.md#0347-2026-02-05](https://github.com/time-rs/time/blob/main/CHANGELOG.md#0347-2026-02-05) |
| Date | 2026-02-05 |
| Patched versions | `>=0.3.47` |
| Unaffected versions | `<0.3.6` |

## Impact

When user-provided input is provided to any type that parses with the RFC 2822 format, a denial of
service attack via stack exhaustion is possible. The attack relies on formally deprecated and
rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary,
non-malicious input will never encounter this scenario.

## Patches

A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned
rather than exhausting the stack.

## Workarounds

Limiting the length of user input is the simplest way to avoid stack exhaustion, as the amount of
the stack consumed would be at most a factor of the length of the input.

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0009.html) for additional details.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.