CVE-2020-35882: Rocket

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in the rocket crate before 0.4.5 for Rust. LocalRequest::clone creates more than one mutable references to the same object, possibly causing a data race.

Affected products

  • Rocket Rocket: from 0.4.0, before 0.4.5 (fixed in 0.4.5)

Published 2020-12-31. Last modified 2026-06-17.