Junglewise Threat Intelligence

CVE-2026-41677: rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length

CVE-2026-41677 · Severity: medium · CVSS 4 · Published 2026-04-22

Technologies: openssl (crates.io). Vendors: crates.io.

Executive brief

The `*_from_pem_callback` APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this.

Affected products

  • crates.io openssl

References

Related threats