The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
CVSS Details
- CVSS 3.1 Base Score: 4.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade clippyUpgrade rust-toolsetUpgrade rust-gdbUpgrade rust-docUpgrade cargoUpgrade rust-toolset-srpm-macrosUpgrade rust-srcUpgrade rust-std-staticUpgrade rust-analyzerUpgrade rust-debugger-commonUpgrade rustUpgrade rustfmt | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade rust-opensslNo solution exists | Jul 31, 2025 | Jul 31, 2025 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jul 28, 2025 |
| Redhat_linux | — | No solution exists | Jul 31, 2025 | Jul 28, 2025 |
| Ubuntu | — | Upgrade librust-openssl-dev (Ubuntu Pro) | Nov 28, 2025 | Nov 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub