Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2026-42327

3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant — resulting in undefined behavior. This vulnerability is fixed in 0.10.79.

EPSS: Низкий
redhat логотип

CVE-2026-42327

3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant — resulting in undefined behavior. This vulnerability is fixed in 0.10.79.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-42327

3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant — resulting in undefined behavior. This vulnerability is fixed in 0.10.79.

EPSS: Низкий
debian логотип

CVE-2026-42327

3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming langua ...

EPSS: Низкий
github логотип

GHSA-xp3w-r5p5-63rr

3 месяца назад

rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21292-1

около 1 месяца назад

Security update for agama

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21294-1

около 1 месяца назад

Security update for python-cryptography

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21285-1

около 1 месяца назад

Security update for python-maturin

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21274-1

около 1 месяца назад

Security update for rust-keylime

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3040-1

26 дней назад

Security update for python-cryptography

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3026-1

26 дней назад

Security update for python-cryptography

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2832-1

около 1 месяца назад

Security update for rustup

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2831-1

около 1 месяца назад

Security update for rustup

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3022-1

26 дней назад

Security update for sccache

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42327

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant — resulting in undefined behavior. This vulnerability is fixed in 0.10.79.

0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-42327

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant — resulting in undefined behavior. This vulnerability is fixed in 0.10.79.

CVSS3: 9.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42327

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant — resulting in undefined behavior. This vulnerability is fixed in 0.10.79.

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-42327

rust-openssl provides OpenSSL bindings for the Rust programming langua ...

0%
Низкий
3 месяца назад
github логотип
GHSA-xp3w-r5p5-63rr

rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs

0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21292-1

Security update for agama

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21294-1

Security update for python-cryptography

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21285-1

Security update for python-maturin

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21274-1

Security update for rust-keylime

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3040-1

Security update for python-cryptography

26 дней назад
suse-cvrf логотип
SUSE-SU-2026:3026-1

Security update for python-cryptography

26 дней назад
suse-cvrf логотип
SUSE-SU-2026:2832-1

Security update for rustup

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2831-1

Security update for rustup

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3022-1

Security update for sccache

26 дней назад

Уязвимостей на страницу