CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-45784

unknowncovered by 2 sourcesfirst seen 2026-07-14
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.

CSIRTS triage

What
A potential out-of-bounds write vulnerability has been identified in the CipherCtxRef::cipher_update_inplace function for AES-KW-PAD ciphers.
Who is affected
Users of rust-openssl are at risk of this vulnerability.
Urgency
Remediation is recommended as the severity is currently unknown.
Action
Update rust-openssl to the latest version to address this vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-45784

Get an email if CVE-2026-45784 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-45784

CVE.org record

Embed the live status

CVE-2026-45784 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-45784 status](https://www.csirts.com/badge/CVE-2026-45784)](https://www.csirts.com/cve/CVE-2026-45784)