The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
CVSS Details
- CVSS 3.1 Base Score: 4.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade rust-docUpgrade rust-gdbUpgrade rust-toolsetUpgrade cargoUpgrade rust-srcUpgrade clippyUpgrade rust-toolset-srpm-macrosUpgrade rust-std-staticUpgrade rust-analyzerUpgrade rust-debugger-commonUpgrade rustUpgrade rustfmt | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade rust-opensslNo solution exists | Jul 31, 2025 | Jul 31, 2025 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jul 28, 2025 |
| Redhat_linux | — | No solution exists | Jul 31, 2025 | Jul 28, 2025 |
| Ubuntu | — | Upgrade librust-openssl-dev (Ubuntu Pro) | Nov 28, 2025 | Nov 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub