openssl
Activity
- Latest release
- 3mo ago
- Total releases
- 174
- Cadence
- ~23 days
- Last 12 months
- 8
Details
- License
- Apache-2.0
- First release
- Nov 21, 2014
| Version | Released | |
|---|---|---|
0.10.81
unknown
|
0.10.81
unknown
Dependencies (7)
|
|
0.10.80
unknown
|
0.10.80
unknown
Dependencies (7)
|
|
0.10.79
unknown
1 CVE
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.79
unknown
Dependencies (7)
|
|
0.10.78
unknown
3 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.78
unknown
Dependencies (8)
|
|
0.10.77
unknown
8 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.77
unknown
Dependencies (8)
|
|
0.10.76
unknown
8 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.76
unknown
Dependencies (8)
|
|
0.10.75
unknown
8 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.75
unknown
Dependencies (8)
|
|
0.10.74
unknown
8 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.74
unknown
Dependencies (8)
|
|
0.10.73
unknown
8 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.73
unknown
Dependencies (8)
|
|
0.10.72
unknown
8 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.72
unknown
Dependencies (8)
|
|
0.10.71
unknown
9 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.71
unknown
Dependencies (8)
|
|
0.10.70
unknown
9 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.70
unknown
Dependencies (8)
|
|
0.10.69
unknown
10 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.69
unknown
Dependencies (8)
|
|
0.10.68
unknown
10 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.68
unknown
Dependencies (8)
|
|
0.10.67
unknown
10 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.67
unknown
Dependencies (8)
|
|
0.10.66
unknown
10 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.66
unknown
Dependencies (8)
|
|
0.10.65
unknown
11 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.65
unknown
Dependencies (8)
|
|
0.10.64
unknown
11 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.64
unknown
Dependencies (8)
|
|
0.10.63
unknown
11 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.63
unknown
Dependencies (8)
|
|
0.10.62
unknown
11 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.62
unknown
Dependencies (8)
|
|
0.10.61
unknown
11 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.61
unknown
Dependencies (8)
|
|
0.10.60
unknown
11 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.10.60
unknown
Dependencies (8)
|
|
0.10.59
unknown
12 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.59
unknown
Dependencies (8)
|
|
0.10.58
unknown
12 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.58
unknown
Dependencies (8)
|
|
0.10.57
unknown
12 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.57
unknown
Dependencies (8)
|
|
0.10.56
unknown
12 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.56
unknown
Dependencies (8)
|
|
0.10.55
unknown
12 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.55
unknown
Dependencies (8)
|
|
0.10.54
unknown
13 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.54
unknown
Dependencies (8)
|
|
0.10.53
unknown
13 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.53
unknown
Dependencies (8)
|
|
0.10.52
unknown
13 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.52
unknown
Dependencies (8)
|
|
0.10.51
unknown
13 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.51
unknown
Dependencies (8)
|
|
0.10.50
unknown
13 CVEs
CVE-2026-45784
GHSA-phqj-4mhp-q6mq
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. This method was missed in the fix for GHSA-xv59-967r-8726 Fixed in
0.10.80
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.50
unknown
Dependencies (8)
|
|
0.10.49
unknown
12 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.49
unknown
Dependencies (8)
|
|
0.10.48
unknown
12 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.48
unknown
Dependencies (8)
|
|
0.10.47
unknown
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.47
unknown
Dependencies (8)
|
|
0.10.46
unknown
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.46
unknown
Dependencies (8)
|
|
0.10.45
unknown
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.45
unknown
Dependencies (8)
|
|
0.10.44
unknown
yanked
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.44
unknown
yanked
Dependencies (8)
|
|
0.10.43
unknown
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.43
unknown
Dependencies (8)
|
|
0.10.42
unknown
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.42
unknown
Dependencies (8)
|
|
0.10.41
unknown
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.41
unknown
Dependencies (8)
|
|
0.10.40
unknown
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.40
unknown
Dependencies (8)
|
|
0.10.39
unknown
15 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41681
GHSA-ghm9-cr32-g9qj
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-4fcv-w3qc-ppgg
RUSTSEC-2025-0022
Apr 04, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Medium
Network
High
None
None
When a In practice this would nearly always result in OpenSSL treating the properties as an empty string (due to The maintainers thank quitbug for reporting this vulnerability to us. Fixed in
0.10.72
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.39
unknown
Dependencies (8)
|
|
0.10.38
unknown
13 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.38
unknown
Dependencies (8)
|
|
0.10.37
unknown
13 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.37
unknown
Dependencies (8)
|
|
0.10.36
unknown
13 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.36
unknown
Dependencies (8)
|
|
0.10.35
unknown
13 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.35
unknown
Dependencies (8)
|
|
0.10.34
unknown
13 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.34
unknown
Dependencies (8)
|
|
0.10.33
unknown
13 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.33
unknown
Dependencies (8)
|
|
0.10.32
unknown
13 CVEs
CVE-2026-44662
GHSA-xv59-967r-8726
May 07, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Medium
Local
Low
None
None
This only impacts users using AES key-wrap-with-padding ciphers. Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42327
GHSA-xp3w-r5p5-63rr
May 05, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
Network
Low
None
None
Fixed in
0.10.79
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41676
GHSA-pqf5-4pqq-29f5
Apr 22, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
Network
Low
None
None
Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41677
GHSA-xmgf-hq76-4vx2
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
Network
Low
None
None
The Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41678
GHSA-8c75-8mhr-p7r9
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
Network
Low
None
None
Summary
Details
Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of ImpactVulnerable applications using AES keywrap and allowing attacker controlled buffer sizes could have an attacker trigger an out-of-bounds write. Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41898
GHSA-hppc-g8h3-xhp3
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
Network
Low
None
None
The FFI trampolines behind Fixed in
0.10.78
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24898
GHSA-rpmj-rpgj-qmpm
RUSTSEC-2025-0004
Feb 03, 2025
rust-openssl ssl::select_next_proto use after free
Medium
Network
High
None
None
Impact
Patches
WorkaroundsIn standard usage of Not vulnerable - the server buffer has a
Not vulnerable - the server buffer outlives the handshake:
Vulnerable - the server buffer is freed when the callback returns:
Referenceshttps://github.com/sfackler/rust-openssl/pull/2360 Fixed in
0.10.70
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-q445-7m23-qrmw
RUSTSEC-2024-0357
Jul 22, 2024
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Medium
Network
Low
None
None
Previously, Fixed in
0.10.66
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-xphf-cx8h-7q9g
RUSTSEC-2023-0072
Nov 28, 2023
`openssl` `X509StoreRef::objects` is unsound
Medium
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back. Use of this function should be replaced with Fixed in
0.10.60
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53159
GHSA-xcf7-rvmh-g6q4
RUSTSEC-2023-0044
Jun 21, 2023
`openssl` `X509VerifyParamRef::set_host` buffer over-read
4.5
/ 10
Medium
Local
High
None
None
Changed
Low
None
Low
When this function was passed an empty string, Fixed in
0.10.55
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-3gxf-9r58-2ghg
RUSTSEC-2023-0022
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Medium
OpenSSL has a Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-9qwg-crg9-m2vc
RUSTSEC-2023-0023
Mar 24, 2023
`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
High
Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev
GHSA-6hcf-g6gr-hhcr
RUSTSEC-2023-0024
Mar 24, 2023
`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
High
These functions would crash when the context argument was None with certain extension types. Thanks to David Benjamin (Google) for reporting this issue. Fixed in
0.10.48
References Updated Nov 08, 2023 · Source: OSV.dev |
0.10.32
unknown
Dependencies (8)
|