---
id: CVE-2026-41898
title: rust-openssl provides OpenSSL bindings for the Rust programming language
summary: >-
  rust-openssl provides OpenSSL bindings for the Rust programming language. 
  From 0.9.24 to before 0.10.78, the FFI trampolines behind
  SslContextBuilder::set_psk_client_callback, set_psk_server_callback,
  set_cookie_generate_cb, and set_sta…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-126
  - CWE-130
vendor: rust-openssl_project
product: rust-openssl
affected:
  - 'rust-openssl >= 0.9.24, < 0.10.78'
patched:
  - rust-openssl 0.10.78
published: '2026-04-24'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41898'
references:
  - url: >-
      https://github.com/rust-openssl/rust-openssl/commit/1d109020d98fff2fb2e45c39a373af3dff99b24c
    label: security-advisories@github.com
  - url: 'https://github.com/rust-openssl/rust-openssl/pull/2607'
    label: security-advisories@github.com
  - url: 'https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.78'
    label: security-advisories@github.com
  - url: >-
      https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-hppc-g8h3-xhp3
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0028
epssPercentile: 0.20806
ingestedAt: '2026-07-16T02:48:54.878Z'
---

## Overview

rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78.

## Affected

- `rust-openssl >= 0.9.24, < 0.10.78`

## Remediation

Upgrade past the affected range:

- `rust-openssl 0.10.78`
