{"id":"CVE-2026-41681","title":"rust-openssl provides OpenSSL bindings for the Rust programming language","summary":"rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writ…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-121"],"vendor":"rust-openssl_project","product":"rust-openssl","affected":["rust-openssl >= 0.10.39, < 0.10.78"],"patched":["rust-openssl 0.10.78"],"published":"2026-04-24","updated":"2026-07-15","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41681","references":[{"url":"https://github.com/rust-openssl/rust-openssl/commit/826c3888b77add418b394770e2b2e3a72d9f92fe","label":"security-advisories@github.com"},{"url":"https://github.com/rust-openssl/rust-openssl/pull/2608","label":"security-advisories@github.com"},{"url":"https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.78","label":"security-advisories@github.com"},{"url":"https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-ghm9-cr32-g9qj","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00359,"epssPercentile":0.29765,"ingestedAt":"2026-07-16T02:48:54.858Z","slug":"CVE-2026-41681","body":"## Overview\n\nrust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the stack. This is reachable from safe Rust. This vulnerability is fixed in 0.10.78.\n\n## Affected\n\n- `rust-openssl >= 0.10.39, < 0.10.78`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `rust-openssl 0.10.78`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}