{"schema_version":1,"title":"openssl-src (crates.io) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 26 vulnerabilities in openssl-src (crates.io): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2023-0215, was published on 7 February 2023.","url":"https://junglewise.ai/threats/technologies/openssl-src","json_url":"https://junglewise.ai/threats/technologies/openssl-src.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openssl-src","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":26,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2023-0215","cvss":3.1,"epss":0.0449,"slug":"cve-2023-0215-openssl-src-vulnerable-to-use-after-free-following-bio-new-ndef","title":"RUSTSEC-2023-0009 - Use-after-free following `BIO_new_NDEF`","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0215-openssl-src-vulnerable-to-use-after-free-following-bio-new-ndef"},{"cve":"CVE-2022-4203","cvss":3.1,"epss":0.0139,"slug":"cve-2022-4203-openssl-src-contains-read-buffer-overflow-in-x-509-name-constraint","title":"RUSTSEC-2023-0008 - X.509 Name Constraints Read Buffer Overflow","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4203-openssl-src-contains-read-buffer-overflow-in-x-509-name-constraint"},{"cve":"CVE-2023-0286","cvss":3.1,"epss":0.595,"slug":"cve-2023-0286-vulnerable-openssl-included-in-cryptography-wheels","title":"RUSTSEC-2023-0006 - X.400 address type confusion in X.509 `GeneralName`","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0286-vulnerable-openssl-included-in-cryptography-wheels"},{"cve":"CVE-2023-0401","cvss":3.1,"epss":0.0185,"slug":"cve-2023-0401-openssl-src-contains-null-dereference-during-pkcs7-data","title":"RUSTSEC-2023-0013 - `NULL` dereference during PKCS7 data verification","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0401-openssl-src-contains-null-dereference-during-pkcs7-data"},{"cve":"CVE-2023-0217","cvss":3.1,"epss":0.0185,"slug":"cve-2023-0217-openssl-src-subject-to-null-dereference-validating-dsa-public-key","title":"RUSTSEC-2023-0012 - `NULL` dereference validating DSA public key","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0217-openssl-src-subject-to-null-dereference-validating-dsa-public-key"},{"cve":"CVE-2023-0216","cvss":3.1,"epss":0.0185,"slug":"cve-2023-0216-openssl-src-subject-to-invalid-pointer-dereference-in-d2i-pkcs7","title":"RUSTSEC-2023-0011 - Invalid pointer dereference in `d2i_PKCS7` functions","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0216-openssl-src-subject-to-invalid-pointer-dereference-in-d2i-pkcs7"},{"cve":"CVE-2022-4304","cvss":3.1,"epss":0.162,"slug":"cve-2022-4304-hitachi-energy-gms600-observable-discrepancy-in-openssl-rsa","title":"RUSTSEC-2023-0007 - Timing Oracle in RSA Decryption","severity":"high","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4304-hitachi-energy-gms600-observable-discrepancy-in-openssl-rsa"},{"cve":"CVE-2022-4450","cvss":3.1,"epss":0.2044,"slug":"cve-2022-4450-openssl-src-contains-double-free-after-calling-pem-read-bio-ex","title":"RUSTSEC-2023-0010 - Double free after calling `PEM_read_bio_ex`","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4450-openssl-src-contains-double-free-after-calling-pem-read-bio-ex"},{"cve":"CVE-2022-3996","cvss":3.1,"epss":0.0126,"slug":"cve-2022-3996-denial-of-service-by-double-checked-locking-in-openssl-src","title":"Denial of service by double-checked locking in openssl-src","severity":"low","exploited":false,"published_at":"2022-12-13T18:30:33+00:00","url":"https://junglewise.ai/threats/cve-2022-3996-denial-of-service-by-double-checked-locking-in-openssl-src"},{"cve":"CVE-2022-3602","cvss":3.1,"epss":0.9077,"slug":"cve-2022-3602-x-509-email-address-4-byte-buffer-overflow","title":"RUSTSEC-2022-0064 - X.509 Email Address 4-byte Buffer Overflow","severity":"low","exploited":false,"published_at":"2022-11-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3602-x-509-email-address-4-byte-buffer-overflow"},{"cve":"CVE-2022-3786","cvss":3.1,"epss":0.9249,"slug":"cve-2022-3786-x-509-email-address-variable-length-buffer-overflow","title":"RUSTSEC-2022-0065 - X.509 Email Address Variable Length Buffer Overflow","severity":"low","exploited":false,"published_at":"2022-11-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3786-x-509-email-address-variable-length-buffer-overflow"},{"cve":"CVE-2022-3358","cvss":3.1,"epss":0.0322,"slug":"cve-2022-3358-using-a-custom-cipher-with-nid-undef-may-lead-to-null-encryption","title":"RUSTSEC-2022-0059 - Using a Custom Cipher with `NID_undef` may lead to NULL encryption","severity":"low","exploited":false,"published_at":"2022-10-11T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3358-using-a-custom-cipher-with-nid-undef-may-lead-to-null-encryption"},{"cve":"CVE-2022-2274","cvss":3.1,"epss":0.4568,"slug":"cve-2022-2274-openssl-src-heap-memory-corruption-with-rsa-private-key-operation","title":"RUSTSEC-2022-0033 - Heap memory corruption with RSA private key operation","severity":"low","exploited":false,"published_at":"2022-07-05T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-2274-openssl-src-heap-memory-corruption-with-rsa-private-key-operation"},{"cve":"CVE-2022-2097","cvss":3.1,"epss":0.049,"slug":"cve-2022-2097-aes-ocb-fails-to-encrypt-some-bytes","title":"RUSTSEC-2022-0032 - AES OCB fails to encrypt some bytes","severity":"low","exploited":false,"published_at":"2022-07-05T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-2097-aes-ocb-fails-to-encrypt-some-bytes"},{"cve":"CVE-2021-3712","cvss":7.4,"epss":0.5045,"slug":"cve-2021-3712-read-buffer-overruns-processing-asn-1-strings","title":"Read buffer overruns processing ASN.1 strings","severity":"high","exploited":false,"published_at":"2022-05-24T19:12:03+00:00","url":"https://junglewise.ai/threats/cve-2021-3712-read-buffer-overruns-processing-asn-1-strings"},{"cve":"CVE-2022-1434","cvss":3.1,"epss":0.0106,"slug":"cve-2022-1434-incorrect-mac-key-used-in-the-rc4-md5-ciphersuite","title":"RUSTSEC-2022-0026 - Incorrect MAC key used in the RC4-MD5 ciphersuite","severity":"low","exploited":false,"published_at":"2022-05-03T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-1434-incorrect-mac-key-used-in-the-rc4-md5-ciphersuite"},{"cve":"CVE-2022-1473","cvss":3.1,"epss":0.0252,"slug":"cve-2022-1473-resource-leakage-when-decoding-certificates-and-keys","title":"RUSTSEC-2022-0025 - Resource leakage when decoding certificates and keys","severity":"low","exploited":false,"published_at":"2022-05-03T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-1473-resource-leakage-when-decoding-certificates-and-keys"},{"cve":"CVE-2022-1343","cvss":3.1,"epss":0.0124,"slug":"cve-2022-1343-ocsp-basic-verify-may-incorrectly-verify-the-response-signing","title":"RUSTSEC-2022-0027 - `OCSP_basic_verify` may incorrectly verify the response signing certificate","severity":"low","exploited":false,"published_at":"2022-05-03T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-1343-ocsp-basic-verify-may-incorrectly-verify-the-response-signing"},{"cve":"CVE-2022-0778","cvss":3.1,"epss":0.7319,"slug":"cve-2022-0778-openssl-src-s-infinite-loop-in-bn-mod-sqrt-reachable-when-parsing","title":"RUSTSEC-2022-0014 - Infinite loop in `BN_mod_sqrt()` reachable when parsing certificates","severity":"low","exploited":false,"published_at":"2022-03-15T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-0778-openssl-src-s-infinite-loop-in-bn-mod-sqrt-reachable-when-parsing"},{"cve":"CVE-2021-4044","cvss":3.1,"epss":0.501,"slug":"cve-2021-4044-invalid-handling-of-x509-verify-cert-internal-errors-in-libssl","title":"RUSTSEC-2021-0129 - Invalid handling of `X509_verify_cert()` internal errors in libssl","severity":"low","exploited":false,"published_at":"2021-12-14T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-4044-invalid-handling-of-x509-verify-cert-internal-errors-in-libssl"},{"cve":"CVE-2021-3711","cvss":3.1,"epss":0.8782,"slug":"cve-2021-3711-sm2-decryption-buffer-overflow","title":"RUSTSEC-2021-0097 - SM2 Decryption Buffer Overflow","severity":"low","exploited":false,"published_at":"2021-08-24T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3711-sm2-decryption-buffer-overflow"},{"cve":"CVE-2021-23841","cvss":3.1,"epss":0.0741,"slug":"cve-2021-23841-integer-overflow-in-openssl-src","title":"RUSTSEC-2021-0058 - Null pointer deref in `X509_issuer_and_serial_hash()`","severity":"low","exploited":false,"published_at":"2021-05-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-23841-integer-overflow-in-openssl-src"},{"cve":"CVE-2021-3450","cvss":3.1,"epss":0.1834,"slug":"cve-2021-3450-certificate-check-bypass-in-openssl-src","title":"RUSTSEC-2021-0056 - CA certificate check bypass with X509_V_FLAG_X509_STRICT","severity":"low","exploited":false,"published_at":"2021-05-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3450-certificate-check-bypass-in-openssl-src"},{"cve":"CVE-2021-3449","cvss":3.1,"epss":0.6354,"slug":"cve-2021-3449-openssl-src-null-pointer-dereference-in-signature-algorithms","title":"RUSTSEC-2021-0055 - NULL pointer deref in signature_algorithms processing","severity":"low","exploited":false,"published_at":"2021-05-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3449-openssl-src-null-pointer-dereference-in-signature-algorithms"},{"cve":"CVE-2021-23840","cvss":3.1,"epss":0.5073,"slug":"cve-2021-23840-integer-overflow-in-openssl-src","title":"RUSTSEC-2021-0057 - Integer overflow in CipherUpdate","severity":"low","exploited":false,"published_at":"2021-05-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-23840-integer-overflow-in-openssl-src"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"surrealdb (crates.io)","slug":"surrealdb","vulnerabilities":118,"url":"https://junglewise.ai/threats/technologies/surrealdb"},{"name":"coreutils (crates.io)","slug":"crates-io-coreutils","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/crates-io-coreutils"},{"name":"wasmtime (crates.io)","slug":"wasmtime","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/wasmtime"},{"name":"deno (crates.io)","slug":"deno","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/deno"},{"name":"zebrad (crates.io)","slug":"zebrad","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/zebrad"},{"name":"openssl (crates.io)","slug":"crates-io-openssl","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/crates-io-openssl"},{"name":"rustfs (crates.io)","slug":"rustfs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/rustfs"},{"name":"ckb (crates.io)","slug":"ckb","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/ckb"},{"name":"diesel (crates.io)","slug":"diesel","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/diesel"},{"name":"pyo3 (crates.io)","slug":"pyo3","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/pyo3"},{"name":"russh (crates.io)","slug":"crates-io-russh","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/crates-io-russh"},{"name":"deepseek-tui (crates.io)","slug":"deepseek-tui","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/deepseek-tui"}],"technology":{"hub":true,"name":"openssl-src (crates.io)","slug":"openssl-src","vendor":{"name":"crates.io","slug":"crates-io","url":"https://junglewise.ai/threats/vendors/crates-io"},"aliases":[],"homepage":"https://crates.io/crates/openssl-src","repo_url":"https://github.com/alexcrichton/openssl-src-rs","description":"The openssl-src crate provides the source code of OpenSSL and logic to build it for Rust applications.","url":"https://junglewise.ai/threats/technologies/openssl-src"},"most_severe":[{"cve":"CVE-2021-3712","cvss":7.4,"epss":0.5045,"slug":"cve-2021-3712-read-buffer-overruns-processing-asn-1-strings","title":"Read buffer overruns processing ASN.1 strings","severity":"high","exploited":false,"published_at":"2022-05-24T19:12:03+00:00","url":"https://junglewise.ai/threats/cve-2021-3712-read-buffer-overruns-processing-asn-1-strings"},{"cve":"CVE-2022-4304","cvss":3.1,"epss":0.162,"slug":"cve-2022-4304-hitachi-energy-gms600-observable-discrepancy-in-openssl-rsa","title":"RUSTSEC-2023-0007 - Timing Oracle in RSA Decryption","severity":"high","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4304-hitachi-energy-gms600-observable-discrepancy-in-openssl-rsa"},{"cve":"CVE-2022-3786","cvss":3.1,"epss":0.9249,"slug":"cve-2022-3786-x-509-email-address-variable-length-buffer-overflow","title":"RUSTSEC-2022-0065 - X.509 Email Address Variable Length Buffer Overflow","severity":"low","exploited":false,"published_at":"2022-11-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3786-x-509-email-address-variable-length-buffer-overflow"},{"cve":"CVE-2022-3602","cvss":3.1,"epss":0.9077,"slug":"cve-2022-3602-x-509-email-address-4-byte-buffer-overflow","title":"RUSTSEC-2022-0064 - X.509 Email Address 4-byte Buffer Overflow","severity":"low","exploited":false,"published_at":"2022-11-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3602-x-509-email-address-4-byte-buffer-overflow"},{"cve":"CVE-2021-3711","cvss":3.1,"epss":0.8782,"slug":"cve-2021-3711-sm2-decryption-buffer-overflow","title":"RUSTSEC-2021-0097 - SM2 Decryption Buffer Overflow","severity":"low","exploited":false,"published_at":"2021-08-24T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3711-sm2-decryption-buffer-overflow"},{"cve":"CVE-2022-0778","cvss":3.1,"epss":0.7319,"slug":"cve-2022-0778-openssl-src-s-infinite-loop-in-bn-mod-sqrt-reachable-when-parsing","title":"RUSTSEC-2022-0014 - Infinite loop in `BN_mod_sqrt()` reachable when parsing certificates","severity":"low","exploited":false,"published_at":"2022-03-15T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-0778-openssl-src-s-infinite-loop-in-bn-mod-sqrt-reachable-when-parsing"},{"cve":"CVE-2021-3449","cvss":3.1,"epss":0.6354,"slug":"cve-2021-3449-openssl-src-null-pointer-dereference-in-signature-algorithms","title":"RUSTSEC-2021-0055 - NULL pointer deref in signature_algorithms processing","severity":"low","exploited":false,"published_at":"2021-05-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3449-openssl-src-null-pointer-dereference-in-signature-algorithms"},{"cve":"CVE-2023-0286","cvss":3.1,"epss":0.595,"slug":"cve-2023-0286-vulnerable-openssl-included-in-cryptography-wheels","title":"RUSTSEC-2023-0006 - X.400 address type confusion in X.509 `GeneralName`","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0286-vulnerable-openssl-included-in-cryptography-wheels"},{"cve":"CVE-2020-1967","cvss":3.1,"epss":0.5334,"slug":"cve-2020-1967-null-pointer-deference-in-openssl-src","title":"RUSTSEC-2020-0015 - Crash causing Denial of Service attack","severity":"low","exploited":false,"published_at":"2020-04-25T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-1967-null-pointer-deference-in-openssl-src"},{"cve":"CVE-2021-23840","cvss":3.1,"epss":0.5073,"slug":"cve-2021-23840-integer-overflow-in-openssl-src","title":"RUSTSEC-2021-0057 - Integer overflow in CipherUpdate","severity":"low","exploited":false,"published_at":"2021-05-01T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-23840-integer-overflow-in-openssl-src"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}