Vulnerabilities in rust-openssl
8 resultsVexday analysis
A biblioteca rust-openssl apresenta 8 vulnerabilidades registradas, com 3 publicadas nos últimos 90 dias, indicando risco recente moderado. Nenhuma das falhas está sob exploração ativa conhecida (KEV), e não há críticas de CVSS, reduzindo a urgência operacional imediata. A fraqueza dominante é buffer overflow (CWE-787), exigindo atenção em atualizações e validação de entrada em versões antigas.
CVE-2026-41681HIGHrust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length checkEPSS 0.4%CVE-2026-41677LOWrust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized lengthEPSS 0.3%CVE-2026-41676HIGHrust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1EPSS 0.3%CVE-2026-41898HIGHrust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peerEPSS 0.3%CVE-2026-41678HIGHrust-openssl: Incorrect bounds assertion in aes key wrapEPSS 0.3%CVE-2026-42327HIGHrust-openssl: undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsEPSS 0.2%CVE-2026-44662MEDIUMrust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-paddingEPSS 0.2%CVE-2026-45784MEDIUMrust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersEPSS 0.1%