CVE-2018-25023: Servo Smallvec

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.

Affected products

  • Servo Smallvec: before 0.6.13 (fixed in 0.6.13)

Published 2021-12-27. Last modified 2026-06-17.