CVE-2026-42327
Description
A flaw was found in rust-openssl, a library providing OpenSSL bindings for the Rust programming language. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate. This certificate, containing non-UTF-8 characters in its OCSP (Online Certificate Status Protocol) access location, can cause the application to process an invalid string. This leads to undefined behavior, which may allow an attacker to achieve arbitrary code execution or cause a denial of service.
Statement
This is an Important flaw in rust-openssl that could lead to arbitrary code execution or denial of service. A remote attacker could exploit this by providing a malformed certificate containing non-UTF-8 characters in the OCSP access location, causing applications using rust-openssl to process an invalid string and trigger undefined behavior. This is critical as it can be exploited remotely without user interaction.
Understanding the Weakness (CWE)
Other
Technical Impact: Quality Degradation; Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.