Speykious/cve-rs

Blazingly 🔥 fast 🚀 memory vulnerabilities, written in 100% safe Rust. 🦀

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 45 minutes ago
Added to GitGenius on September 12th, 2026
Created on February 16th, 2024
Open Issues & Pull Requests: 25 (+0)
GitHub issues: Enabled
Number of forks: 113
Total Stargazers: 5,425 (+0)
Total Subscribers: 26 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 5.3 days
Mean response time: 108.7 days
90th percentile: 373.6 days
Tracked items: 12

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 10
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 624 days
Stale 30+ days: 10
Stale 90+ days: 9

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • Java (1)
  • nope (1)
  • too powerful (1)
  • why (1)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

cve-rs is a Rust library that allows you to introduce common memory vulnerabilities into your program while maintaining memory safety.

The tool addresses the limitation that safe Rust prevents you from writing code that could corrupt memory. cve-rs solves this by implementing memory vulnerabilities—use-after-free, buffer overflow, and segmentation faults—entirely in safe Rust code without any unsafe blocks. It achieves this through safe reimplementations of dangerous operations like transmute and null reference creation, allowing developers to simulate or test vulnerability behavior without actually compromising memory safety.

The project is suitable for developers who need to test how their Rust programs handle memory corruption scenarios, educational purposes, or security research. It supports both standard Rust compilation and WebAssembly through WASI, as well as browser-based WebAssembly execution. The tool's entire codebase uses #![deny(unsafe_code)], meaning there are no unsafe blocks in the implementation itself, which is unusual for a library designed to simulate unsafe behavior.

The project maintains a lighthearted tone throughout its documentation and appears to be a proof-of-concept or educational tool rather than production software, as indicated by its licensing choice and the humorous framing of its capabilities.