{"id":"CVE-2023-53159","title":"The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.","summary":"The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.","severity":"medium","cvss":4.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L","cwe":["CWE-126"],"vendor":"sfackler","product":"openssl","affected":["openssl < 0.10.55"],"patched":["openssl 0.10.55"],"published":"2025-07-28","updated":"2026-09-17","sourceUpdated":"2026-09-17T16:42:20.210","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-53159","references":[{"url":"https://crates.io/crates/openssl","label":"cve@mitre.org"},{"url":"https://github.com/sfackler/rust-openssl/issues/1965","label":"cve@mitre.org"},{"url":"https://rustsec.org/advisories/RUSTSEC-2023-0044.html","label":"cve@mitre.org"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-53159.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-53159"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2383808"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-53159"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53159"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00192,"epssPercentile":0.09119,"ingestedAt":"2026-09-17T17:23:30.591Z","scores":{"nvd":4.5,"vendor":5.7},"slug":"CVE-2023-53159","body":"## Overview\n\nThe openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.\n\n## Affected\n\n- `openssl < 0.10.55`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openssl 0.10.55`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Logging Subsystem for Red Hat OpenShift, OpenShift Service Mesh 3, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · no fix planned: Logging Subsystem for Red Hat OpenShift, OpenShift Service Mesh 3, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-53159.json)","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":24.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}