Junglewise Threat Intelligence

CVE-2026-42327: rust-openssl undefined behavior in X509Ref::ocsp_responders

CVE-2026-42327 · Severity: high · CVSS 4 · Published 2026-05-14

Technologies: openssl (crates.io). Vendors: crates.io.

Executive brief

A security vulnerability exists in the Rust bindings for OpenSSL, a library used by many applications to handle secure communications and digital certificates. When processing a specially crafted digital certificate containing invalid data in its web address fields, the library may experience 'undefined behavior,' which can lead to unpredictable system crashes or memory corruption. This could allow an attacker to compromise the integrity of applications that validate or process these certificates.

Technical details

The vulnerability exists in the `X509Ref::ocsp_responders` function within the `rust-openssl` crate. The function retrieves OCSP responder URLs from a certificate's Authority Information Access (AIA) extension and returns them as an `OpensslString`. This type implements `Deref<Target = str>` by calling `str::from_utf8_unchecked` on the raw bytes provided by OpenSSL. Because OpenSSL does not strictly enforce that IA5String fields contain only ASCII/UTF-8 data, a certificate containing non-UTF-8 bytes in the `accessLocation` field will cause safe Rust code to create an invalid `&str` reference. This violation of Rust's UTF-8 invariant results in undefined behavior, which can be triggered by any network-reachable service that parses untrusted X.509 certificates. The issue is fixed in version 0.10.79.

Affected products

  • rust-openssl openssl (rust-openssl) >= 0.9.7, < 0.10.79

Timeline

  • 2026-05-04: disclosed
  • 2026-05-05: advisory
  • 2026-05-14: patched: NVD publication and patch confirmation

References

Related threats