{"id":"CVE-2021-25900","aliases":["GHSA-43w2-9j62-hq99","RUSTSEC-2021-0003"],"url":"https://o3.security/vulnerability/CVE-2021-25900","summary":"Buffer overflow in SmallVec::insert_many","details":"An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.","published":"2021-01-26T18:16:22.270Z","modified":"2026-07-09T00:13:02.086566Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01666,"percentile":0.75604,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"crates.io","name":"smallvec","fixedVersion":"0.6.14"},{"ecosystem":"crates.io","name":"smallvec","fixedVersion":"1.6.1"}],"fix":null,"references":[{"type":"FIX","url":"https://rustsec.org/advisories/RUSTSEC-2021-0003.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:13:02.086566Z"}}