The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
CVSS Details
- CVSS 3.1 Base Score: 4.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade rust-analyzerUpgrade rust-std-staticUpgrade rust-debugger-commonUpgrade rustfmtUpgrade rustUpgrade clippyUpgrade cargoUpgrade rust-srcUpgrade rust-docUpgrade rust-gdbUpgrade rust-toolsetUpgrade rust-toolset-srpm-macros | May 20, 2026 | May 20, 2026 |
| Debian | — | No solution existsUpgrade rust-openssl | Jul 31, 2025 | Jul 31, 2025 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jul 28, 2025 |
| Redhat_linux | — | No solution exists | Jul 31, 2025 | Jul 28, 2025 |
| Ubuntu | — | Upgrade librust-openssl-dev (Ubuntu Pro) | Nov 28, 2025 | Nov 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub