CVE-2026-41678Disclosure(rust-openssl_project / rust-openssl)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of out by in_.len() - 8 - out.len() bytes, causing an out-of-bounds write from a safe public function. This vulnerability is fixed in 0.10.78.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rust-openssl

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-24)
  • 3 total mentions across 2 days

Affected systems

Products
rust-openssl

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-23: 1Mentions · 2026-04-24: 2Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 204-2304-24
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-04-242
Disclosure2
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    rust-openssl has an incorrect bounds assertion in its AES key wrap, risking data integrity/confidentiality. #CVE-2026-41678 #rust #cryptography. Monitor for updates. https://www.pulsepatch.io/posts/cve-2026-41678-rust-openssl-aes-key-wrap

    Post summary

    Announcement of a bounds assertion flaw in rust-openssl's AES key wrap that could compromise data integrity and confidentiality; no PoC, exploit, patch, or active exploitation details provided.

    0001088
    12 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41678 rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that … https://www.cve.org/CVERecord?id=CVE-2026-41678

    Post summary

    The CVE-2026-41678 disclosure notes an incorrect assertion in rust-openssl's aes::unwrap_key() for versions before 0.10.78, without providing a PoC, exploit, or patch.

    00000148
    57.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 openssl crate, Out-of-bounds write, #CVE-2026-41678 (Critical) https://dailycve.com/openssl-crate-out-of-bounds-write-cve-2026-41678-critical/

    Post summary

    The post reports a critical out‑of‑bounds write vulnerability (CVE-2026-41678) in the openssl crate, but provides no PoC, exploit, or mitigation details.

    0000043
    183 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprust-openssl_projectrust-openssl-rust-

Explore more