{"schema_version":1,"title":"openssl (crates.io) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 25 vulnerabilities in openssl (crates.io): 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-45784, was published on 17 July 2026.","url":"https://junglewise.ai/threats/technologies/crates-io-openssl","json_url":"https://junglewise.ai/threats/technologies/crates-io-openssl.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/crates-io-openssl","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":25,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":8},"latest":[{"cve":"CVE-2026-45784","cvss":4,"epss":0.002,"slug":"cve-2026-45784-rust-openssl-heap-overflow-in-cipherctxref-cipher-update-inplace","title":"rust-openssl heap overflow in CipherCtxRef::cipher_update_inplace","severity":"medium","exploited":false,"published_at":"2026-07-17T21:17:06.503+00:00","url":"https://junglewise.ai/threats/cve-2026-45784-rust-openssl-heap-overflow-in-cipherctxref-cipher-update-inplace"},{"cve":"CVE-2026-44662","cvss":4,"epss":0.0017,"slug":"cve-2026-44662-rust-openssl-heap-buffer-overflow-in-aes-key-wrap-with-padding","title":"rust-openssl heap buffer overflow in AES key-wrap-with-padding","severity":"medium","exploited":false,"published_at":"2026-05-14T21:16:47.237+00:00","url":"https://junglewise.ai/threats/cve-2026-44662-rust-openssl-heap-buffer-overflow-in-aes-key-wrap-with-padding"},{"cve":"CVE-2026-42327","cvss":4,"epss":0.0027,"slug":"cve-2026-42327-rust-openssl-undefined-behavior-in-x509ref-ocsp-responders","title":"rust-openssl undefined behavior in X509Ref::ocsp_responders","severity":"high","exploited":false,"published_at":"2026-05-14T21:16:45.43+00:00","url":"https://junglewise.ai/threats/cve-2026-42327-rust-openssl-undefined-behavior-in-x509ref-ocsp-responders"},{"cve":"CVE-2026-41898","cvss":5.3,"epss":0.0045,"slug":"cve-2026-41898-rust-openssl-buffer-over-read-in-psk-and-cookie-callbacks","title":"rust-openssl buffer over-read in PSK and cookie callbacks","severity":"high","exploited":false,"published_at":"2026-04-24T18:16:29.86+00:00","url":"https://junglewise.ai/threats/cve-2026-41898-rust-openssl-buffer-over-read-in-psk-and-cookie-callbacks"},{"cve":"CVE-2026-41681","cvss":9.8,"epss":0.0062,"slug":"cve-2026-41681-rust-openssl-stack-buffer-overflow-in-mdctxref-digest-final","title":"rust-openssl stack buffer overflow in MdCtxRef::digest_final","severity":"critical","exploited":false,"published_at":"2026-04-24T18:16:29.717+00:00","url":"https://junglewise.ai/threats/cve-2026-41681-rust-openssl-stack-buffer-overflow-in-mdctxref-digest-final"},{"cve":"CVE-2026-41678","cvss":8.1,"epss":0.0045,"slug":"cve-2026-41678-rust-openssl-out-of-bounds-write-in-aes-unwrap-key","title":"rust-openssl out-of-bounds write in aes::unwrap_key","severity":"high","exploited":false,"published_at":"2026-04-24T18:16:29.42+00:00","url":"https://junglewise.ai/threats/cve-2026-41678-rust-openssl-out-of-bounds-write-in-aes-unwrap-key"},{"cve":"CVE-2026-41676","cvss":7.5,"epss":0.0046,"slug":"cve-2026-41676-rust-openssl-buffer-overflow-in-deriver-derive","title":"rust-openssl buffer overflow in Deriver::derive","severity":"high","exploited":false,"published_at":"2026-04-24T18:16:29.12+00:00","url":"https://junglewise.ai/threats/cve-2026-41676-rust-openssl-buffer-overflow-in-deriver-derive"},{"cve":"CVE-2026-41677","cvss":4,"epss":0.0051,"slug":"cve-2026-41677-rust-opennssl-has-an-out-of-bounds-read-in-pem-password-callback","title":"rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length","severity":"medium","exploited":false,"published_at":"2026-04-22T21:20:04+00:00","url":"https://junglewise.ai/threats/cve-2026-41677-rust-opennssl-has-an-out-of-bounds-read-in-pem-password-callback"},{"cvss":3.1,"slug":"duplicate-advisory-openssl-x509verifyparamref-set-host-buffer-over-read-b24aefb6","title":"Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read","severity":"low","exploited":false,"published_at":"2025-07-28T03:31:04+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-openssl-x509verifyparamref-set-host-buffer-over-read-b24aefb6"},{"cvss":4,"slug":"rust-openssl-use-after-free-in-md-fetch-and-cipher-fetch-b7e7dd01","title":"rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`","severity":"medium","exploited":false,"published_at":"2025-04-04T20:31:08+00:00","url":"https://junglewise.ai/threats/rust-openssl-use-after-free-in-md-fetch-and-cipher-fetch-b7e7dd01"},{"slug":"rustsec-2025-0022-use-after-free-in-md-fetch-and-cipher-fetch-1c473b89","title":"RUSTSEC-2025-0022 - Use-After-Free in `Md::fetch` and `Cipher::fetch`","severity":"info","exploited":false,"published_at":"2025-04-04T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2025-0022-use-after-free-in-md-fetch-and-cipher-fetch-1c473b89"},{"cve":"CVE-2025-24898","cvss":4,"epss":0.0068,"slug":"cve-2025-24898-rust-openssl-ssl-select-next-proto-use-after-free","title":"RUSTSEC-2025-0004 - ssl::select_next_proto use after free","severity":"medium","exploited":false,"published_at":"2025-02-02T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-24898-rust-openssl-ssl-select-next-proto-use-after-free"},{"cvss":3.1,"slug":"openssl-s-membio-get-buf-has-undefined-behavior-with-empty-buffers-463bbd74","title":"openssl's `MemBio::get_buf` has undefined behavior with empty buffers","severity":"low","exploited":false,"published_at":"2024-07-22T17:34:53+00:00","url":"https://junglewise.ai/threats/openssl-s-membio-get-buf-has-undefined-behavior-with-empty-buffers-463bbd74"},{"slug":"rustsec-2024-0357-membio-get-buf-has-undefined-behavior-with-empty-cdd3fe86","title":"RUSTSEC-2024-0357 - `MemBio::get_buf` has undefined behavior with empty buffers","severity":"info","exploited":false,"published_at":"2024-07-21T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2024-0357-membio-get-buf-has-undefined-behavior-with-empty-cdd3fe86"},{"slug":"openssl-x509storeref-objects-is-unsound-c3070164","title":"`openssl` `X509StoreRef::objects` is unsound","severity":"info","exploited":false,"published_at":"2023-11-28T20:51:08+00:00","url":"https://junglewise.ai/threats/openssl-x509storeref-objects-is-unsound-c3070164"},{"slug":"rustsec-2023-0072-openssl-x509storeref-objects-is-unsound-12c21511","title":"RUSTSEC-2023-0072 - `openssl` `X509StoreRef::objects` is unsound","severity":"info","exploited":false,"published_at":"2023-11-23T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2023-0072-openssl-x509storeref-objects-is-unsound-12c21511"},{"cve":"CVE-2023-53159","cvss":3.1,"epss":0.0019,"slug":"cve-2023-53159-openssl-x509verifyparamref-set-host-buffer-over-read","title":"RUSTSEC-2023-0044 - `openssl` `X509VerifyParamRef::set_host` buffer over-read","severity":"low","exploited":false,"published_at":"2023-06-20T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-53159-openssl-x509verifyparamref-set-host-buffer-over-read"},{"slug":"openssl-x509namebuilder-build-returned-object-is-not-thread-safe-c8567f59","title":"`openssl` `X509NameBuilder::build` returned object is not thread safe","severity":"info","exploited":false,"published_at":"2023-03-24T22:01:35+00:00","url":"https://junglewise.ai/threats/openssl-x509namebuilder-build-returned-object-is-not-thread-safe-c8567f59"},{"slug":"openssl-subjectalternativename-and-extendedkeyusage-other-allow-5005afcd","title":"`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read","severity":"info","exploited":false,"published_at":"2023-03-24T22:01:29+00:00","url":"https://junglewise.ai/threats/openssl-subjectalternativename-and-extendedkeyusage-other-allow-5005afcd"},{"slug":"openssl-x509extension-new-and-x509extension-new-nid-null-pointer-2a711e9b","title":"`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference","severity":"info","exploited":false,"published_at":"2023-03-24T22:01:23+00:00","url":"https://junglewise.ai/threats/openssl-x509extension-new-and-x509extension-new-nid-null-pointer-2a711e9b"},{"slug":"rustsec-2023-0024-openssl-x509extension-new-and-x509extension-new-nid-256004e6","title":"RUSTSEC-2023-0024 - `openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference","severity":"info","exploited":false,"published_at":"2023-03-24T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2023-0024-openssl-x509extension-new-and-x509extension-new-nid-256004e6"},{"slug":"rustsec-2023-0023-openssl-subjectalternativename-and-extendedkeyusage-6623624d","title":"RUSTSEC-2023-0023 - `openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read","severity":"info","exploited":false,"published_at":"2023-03-24T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2023-0023-openssl-subjectalternativename-and-extendedkeyusage-6623624d"},{"slug":"rustsec-2023-0022-openssl-x509namebuilder-build-returned-object-is-not-eebae594","title":"RUSTSEC-2023-0022 - `openssl` `X509NameBuilder::build` returned object is not thread safe","severity":"info","exploited":false,"published_at":"2023-03-24T12:00:00+00:00","url":"https://junglewise.ai/threats/rustsec-2023-0022-openssl-x509namebuilder-build-returned-object-is-not-eebae594"},{"cve":"CVE-2018-20997","cvss":3,"epss":0.0174,"slug":"cve-2018-20997-use-after-free-in-openssl","title":"RUSTSEC-2018-0010 - Use after free in CMS Signing","severity":"low","exploited":false,"published_at":"2018-06-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2018-20997-use-after-free-in-openssl"},{"cve":"CVE-2016-10931","cvss":3,"epss":0.0075,"slug":"cve-2016-10931-improper-certificate-validation-in-openssl","title":"RUSTSEC-2016-0001 - SSL/TLS MitM vulnerability due to insecure defaults","severity":"low","exploited":false,"published_at":"2016-11-05T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2016-10931-improper-certificate-validation-in-openssl"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"surrealdb (crates.io)","slug":"surrealdb","vulnerabilities":118,"url":"https://junglewise.ai/threats/technologies/surrealdb"},{"name":"coreutils (crates.io)","slug":"crates-io-coreutils","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/crates-io-coreutils"},{"name":"wasmtime (crates.io)","slug":"wasmtime","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/wasmtime"},{"name":"deno (crates.io)","slug":"deno","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/deno"},{"name":"zebrad (crates.io)","slug":"zebrad","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/zebrad"},{"name":"openssl-src (crates.io)","slug":"openssl-src","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/openssl-src"},{"name":"rustfs (crates.io)","slug":"rustfs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/rustfs"},{"name":"ckb (crates.io)","slug":"ckb","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/ckb"},{"name":"diesel (crates.io)","slug":"diesel","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/diesel"},{"name":"pyo3 (crates.io)","slug":"pyo3","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/pyo3"},{"name":"russh (crates.io)","slug":"crates-io-russh","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/crates-io-russh"},{"name":"deepseek-tui (crates.io)","slug":"deepseek-tui","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/deepseek-tui"}],"technology":{"hub":true,"name":"openssl (crates.io)","slug":"crates-io-openssl","vendor":{"name":"crates.io","slug":"crates-io","url":"https://junglewise.ai/threats/vendors/crates-io"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/crates-io-openssl"},"most_severe":[{"cve":"CVE-2026-41681","cvss":9.8,"epss":0.0062,"slug":"cve-2026-41681-rust-openssl-stack-buffer-overflow-in-mdctxref-digest-final","title":"rust-openssl stack buffer overflow in MdCtxRef::digest_final","severity":"critical","exploited":false,"published_at":"2026-04-24T18:16:29.717+00:00","url":"https://junglewise.ai/threats/cve-2026-41681-rust-openssl-stack-buffer-overflow-in-mdctxref-digest-final"},{"cve":"CVE-2026-41678","cvss":8.1,"epss":0.0045,"slug":"cve-2026-41678-rust-openssl-out-of-bounds-write-in-aes-unwrap-key","title":"rust-openssl out-of-bounds write in aes::unwrap_key","severity":"high","exploited":false,"published_at":"2026-04-24T18:16:29.42+00:00","url":"https://junglewise.ai/threats/cve-2026-41678-rust-openssl-out-of-bounds-write-in-aes-unwrap-key"},{"cve":"CVE-2026-41676","cvss":7.5,"epss":0.0046,"slug":"cve-2026-41676-rust-openssl-buffer-overflow-in-deriver-derive","title":"rust-openssl buffer overflow in Deriver::derive","severity":"high","exploited":false,"published_at":"2026-04-24T18:16:29.12+00:00","url":"https://junglewise.ai/threats/cve-2026-41676-rust-openssl-buffer-overflow-in-deriver-derive"},{"cve":"CVE-2026-41898","cvss":5.3,"epss":0.0045,"slug":"cve-2026-41898-rust-openssl-buffer-over-read-in-psk-and-cookie-callbacks","title":"rust-openssl buffer over-read in PSK and cookie callbacks","severity":"high","exploited":false,"published_at":"2026-04-24T18:16:29.86+00:00","url":"https://junglewise.ai/threats/cve-2026-41898-rust-openssl-buffer-over-read-in-psk-and-cookie-callbacks"},{"cve":"CVE-2026-42327","cvss":4,"epss":0.0027,"slug":"cve-2026-42327-rust-openssl-undefined-behavior-in-x509ref-ocsp-responders","title":"rust-openssl undefined behavior in X509Ref::ocsp_responders","severity":"high","exploited":false,"published_at":"2026-05-14T21:16:45.43+00:00","url":"https://junglewise.ai/threats/cve-2026-42327-rust-openssl-undefined-behavior-in-x509ref-ocsp-responders"},{"cve":"CVE-2025-24898","cvss":4,"epss":0.0068,"slug":"cve-2025-24898-rust-openssl-ssl-select-next-proto-use-after-free","title":"RUSTSEC-2025-0004 - ssl::select_next_proto use after free","severity":"medium","exploited":false,"published_at":"2025-02-02T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-24898-rust-openssl-ssl-select-next-proto-use-after-free"},{"cve":"CVE-2026-41677","cvss":4,"epss":0.0051,"slug":"cve-2026-41677-rust-opennssl-has-an-out-of-bounds-read-in-pem-password-callback","title":"rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length","severity":"medium","exploited":false,"published_at":"2026-04-22T21:20:04+00:00","url":"https://junglewise.ai/threats/cve-2026-41677-rust-opennssl-has-an-out-of-bounds-read-in-pem-password-callback"},{"cve":"CVE-2026-45784","cvss":4,"epss":0.002,"slug":"cve-2026-45784-rust-openssl-heap-overflow-in-cipherctxref-cipher-update-inplace","title":"rust-openssl heap overflow in CipherCtxRef::cipher_update_inplace","severity":"medium","exploited":false,"published_at":"2026-07-17T21:17:06.503+00:00","url":"https://junglewise.ai/threats/cve-2026-45784-rust-openssl-heap-overflow-in-cipherctxref-cipher-update-inplace"},{"cve":"CVE-2026-44662","cvss":4,"epss":0.0017,"slug":"cve-2026-44662-rust-openssl-heap-buffer-overflow-in-aes-key-wrap-with-padding","title":"rust-openssl heap buffer overflow in AES key-wrap-with-padding","severity":"medium","exploited":false,"published_at":"2026-05-14T21:16:47.237+00:00","url":"https://junglewise.ai/threats/cve-2026-44662-rust-openssl-heap-buffer-overflow-in-aes-key-wrap-with-padding"},{"cvss":4,"slug":"rust-openssl-use-after-free-in-md-fetch-and-cipher-fetch-b7e7dd01","title":"rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`","severity":"medium","exploited":false,"published_at":"2025-04-04T20:31:08+00:00","url":"https://junglewise.ai/threats/rust-openssl-use-after-free-in-md-fetch-and-cipher-fetch-b7e7dd01"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}