CVE-2026-41898Disclosure(rust-openssl_project / rust-openssl)

MEDIUMCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch rust-openssl_project rust-openssl systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-126CWE-130

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rust-openssl

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
rust-openssl

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-06: 1Active Exploitation · 2026-04-25: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-06: 104-2404-2505-06
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-251
Active Exploitation1
2026-05-061
Disclosure1
Full discourse3 posts
  • EcuCERT@EcuCERT_EC
    Disclosure

    La librería rust-openssl presenta la vulnerabilidad CVE-2026-41898, que causa lectura fuera de límites y desbordamiento de memoria, exponiendo información o fallos del sistema. Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/05/AL-2026-023-Vulnerabilidad-Critica-en-rust-openssl-CVE-2026-41898.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/wrBJ3AT9bD

    Post summary

    The post discloses a rust‑openssl vulnerability (CVE‑2026‑41898) that causes out‑of‑bounds reads and memory overflow, with a link to an Ecuadorian report, but offers no exploit details, patches, or evidence of active exploitation.

    03000261
    2.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41898 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client… https://www.cve.org/CVERecord?id=CVE-2026-41898

    Post summary

    The passage summarizes the CVE’s affected Rust‑openssl versions and the specific vulnerable component, but does not provide proof of exploitation or mitigation.

    00001114
    57.2K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CVE-2026-41898 in rust-openssl is under active exploitation—attackers can leak adjacent memory from OpenSSL, risking data confidentiality. Patch now to protect sensitive info. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #CloudSecurity #AWS #OpenSource https://t.co/oLMHn7ukVI

    Post summary

    CVE-2026‑41898 in rust‑openssl is being actively exploited to leak adjacent memory, so users should apply the patch immediately to prevent data exposure.

    0000037
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprust-openssl_projectrust-openssl-rust-

Explore more