CVE-2026-45784Sfackler · Openssl
Vulnerability data via NVD (ingested)
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-45784product:"Sfackler Openssl"http.html:"Openssl"More intel sources (5)
vuln:CVE-2026-45784vulnerabilities.cve_id: CVE-2026-45784CVE-2026-45784CVE-2026-45784"CVE-2026-45784" exploit -site:nvd.nist.gov