{"id":"GHSA-xmgf-hq76-4vx2","summary":"rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length","details":"The `*_from_pem_callback` APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this.","aliases":["CVE-2026-41677"],"modified":"2026-07-17T21:13:15.031420189Z","published":"2026-04-22T21:20:04Z","database_specific":{"github_reviewed_at":"2026-04-22T21:20:04Z","nvd_published_at":"2026-04-24T18:16:29Z","cwe_ids":["CWE-125","CWE-1284"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-xmgf-hq76-4vx2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41677"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/pull/2605"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/commit/5af6895c907773699f37f583f409b862284062b1"},{"type":"PACKAGE","url":"https://github.com/rust-openssl/rust-openssl"},{"type":"WEB","url":"https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.78"}],"affected":[{"package":{"name":"openssl","ecosystem":"crates.io","purl":"pkg:cargo/openssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.9.0"},{"fixed":"0.10.78"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xmgf-hq76-4vx2/GHSA-xmgf-hq76-4vx2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}]}