Rust-Openssl / Rust-Openssl
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-45784 | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | MEDIUM | 5.1 | Jul 17, 2026 |
| CVE-2026-44662 | rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding | MEDIUM | 5.1 | May 14, 2026 |
| CVE-2026-42327 | rust-openssl: undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs | HIGH | 8.7 | May 14, 2026 |
| CVE-2026-41898 | rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer | HIGH | 8.3 | Apr 24, 2026 |
| CVE-2026-41681 | rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check | HIGH | 8.1 | Apr 24, 2026 |
| CVE-2026-41678 | rust-openssl: Incorrect bounds assertion in aes key wrap | HIGH | 7.2 | Apr 24, 2026 |
| CVE-2026-41677 | rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length | LOW | 1.7 | Apr 24, 2026 |
| CVE-2026-41676 | rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 | HIGH | 7.2 | Apr 24, 2026 |
| CVE-2018-20997 | An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing. | CRITICAL | 9.8 | Aug 26, 2019 |
| CVE-2016-10931 | An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off… | HIGH | 8.1 | Aug 26, 2019 |
Showing 1 to 10 of 10 CVEs