Vulnerable OpenSSL included in cryptography wheels
Modified: 2/4/2026
package
pkg:crates.io/openssl-src
Vulnerable OpenSSL included in cryptography wheels
Modified: 2/4/2026
openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions
Modified: 2/4/2026
AES OCB fails to encrypt some bytes
Modified: 2/4/2026
Using a Custom Cipher with `NID_undef` may lead to NULL encryption
Modified: 2/4/2026
SM2 Decryption Buffer Overflow
Modified: 6/24/2024
Incorrect MAC key used in the RC4-MD5 ciphersuite
Modified: 2/4/2026
openssl-src heap memory corruption with RSA private key operation
Modified: 11/8/2023
openssl-src NULL pointer Dereference in signature_algorithms processing
Modified: 12/16/2024
Integer Overflow in openssl-src
Modified: 11/8/2023
Certificate check bypass in openssl-src
Modified: 12/16/2024
X.509 Email Address 4-byte Buffer Overflow
Modified: 2/4/2026
Resource leakage when decoding certificates and keys
Modified: 2/4/2026
X.509 Email Address Variable Length Buffer Overflow
Modified: 2/4/2026
Null pointer deference in openssl-src
Modified: 2/4/2026
`OCSP_basic_verify` may incorrectly verify the response signing certificate
Modified: 2/4/2026
Invalid handling of `X509_verify_cert()` internal errors in libssl
Modified: 12/16/2024
openssl-src subject to Timing Oracle in RSA Decryption
Modified: 2/4/2026
Read buffer overruns processing ASN.1 strings
Modified: 5/5/2026
Integer Overflow in openssl-src
Modified: 12/16/2024
openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`
Modified: 2/4/2026
openssl-src contains Double free after calling `PEM_read_bio_ex`
Modified: 2/4/2026
Denial of service by double-checked locking in openssl-src
Modified: 2/4/2026
openssl-src contains `NULL` dereference during PKCS7 data verification
Modified: 2/4/2026
openssl-src subject to NULL dereference validating DSA public key
Modified: 2/4/2026
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
Modified: 2/4/2026
openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates
Modified: 2/4/2026
Crash causing Denial of Service attack
Modified: 7/15/2024
NULL pointer deref in signature_algorithms processing
Modified: 12/16/2024
CA certificate check bypass with X509_V_FLAG_X509_STRICT
Modified: 12/16/2024
Integer overflow in CipherUpdate
Modified: 12/16/2024
Null pointer deref in `X509_issuer_and_serial_hash()`
Modified: 11/8/2023
SM2 Decryption Buffer Overflow
Modified: 11/8/2023
Read buffer overruns processing ASN.1 strings
Modified: 11/8/2023
Invalid handling of `X509_verify_cert()` internal errors in libssl
Modified: 12/16/2024
Infinite loop in `BN_mod_sqrt()` reachable when parsing certificates
Modified: 6/10/2025
Resource leakage when decoding certificates and keys
Modified: 11/8/2023
Incorrect MAC key used in the RC4-MD5 ciphersuite
Modified: 11/8/2023
`OCSP_basic_verify` may incorrectly verify the response signing certificate
Modified: 11/8/2023
AES OCB fails to encrypt some bytes
Modified: 11/8/2023
Heap memory corruption with RSA private key operation
Modified: 11/8/2023
Using a Custom Cipher with `NID_undef` may lead to NULL encryption
Modified: 11/8/2023
X.509 Email Address 4-byte Buffer Overflow
Modified: 12/16/2024
X.509 Email Address Variable Length Buffer Overflow
Modified: 12/16/2024
X.400 address type confusion in X.509 `GeneralName`
Modified: 11/8/2023
Timing Oracle in RSA Decryption
Modified: 11/8/2023
X.509 Name Constraints Read Buffer Overflow
Modified: 11/8/2023
Use-after-free following `BIO_new_NDEF`
Modified: 11/8/2023
Double free after calling `PEM_read_bio_ex`
Modified: 11/8/2023
Invalid pointer dereference in `d2i_PKCS7` functions
Modified: 11/8/2023
`NULL` dereference validating DSA public key
Modified: 11/8/2023
`NULL` dereference during PKCS7 data verification
Modified: 11/8/2023