CVE-2026-6654EPSS p6.5%

CVE-2026-6654CVE-2026-6654

mozilla / thin-vec

Description

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.

Scoring

CVSS 5.1 ()
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS0.17% probability of exploitation · percentile 6.5% · 2026-08-12T12:03:51Z
Last modified2026-07-15
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.