VendorsRust-openssl Projectrust-opensslall versions
Vulnerabilities

Rust-openssl Project rust-OpenSSL

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-20997
An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
Published 2019-08-26 · Modified
9.8EPSS 0.017
CVE-2026-41677
rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length
Published 2026-04-24 · Analyzed
9.1EPSS 0.003
CVE-2026-41898
rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer
Published 2026-04-24 · Analyzed
8.3EPSS 0.003
CVE-2016-10931
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.
Published 2019-08-26 · Modified
8.1EPSS 0.007
CVE-2026-41681
rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check
Published 2026-04-24 · Analyzed
8.1EPSS 0.004
CVE-2026-41678
rust-openssl: Incorrect bounds assertion in aes key wrap
Published 2026-04-24 · Analyzed
8.1EPSS 0.003
CVE-2026-41676
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
Published 2026-04-24 · Analyzed
7.5EPSS 0.003