CVE-2026-41898Medium· 5.3▾ Sunlitrust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_sta…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78.
rust-openssl >= 0.9.24, < 0.10.78Upgrade past the affected range:
rust-openssl 0.10.78Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41681High· 7.5rust-openssl provides OpenSSL bindings for the Rust programming language
CVE-2026-41678High· 8.1rust-openssl provides OpenSSL bindings for the Rust programming language
CVE-2026-41676High· 7.5rust-openssl provides OpenSSL bindings for the Rust programming language
CVE-2026-5367High· 8.6A flaw was found in OVN (Open Virtual Network)
CVE-2026-70652Nonelibvips is a fast image processing library with low memory needs
CVE-2023-5778High· 7.5Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controll…