Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
2917
Downloads
3.3M
Verified
2917
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
1 rules matched. Showing 1 loaded rules.
Publish rule
CVE-2026-41898: Rust Openssl Ffi Trampoline Unchecked Callback Lengthcve-2026-41898-rust-openssl-ffi-trampoline-unchecked-callback-length

FFI trampoline forwards a Rust closure's returned `usize` length directly to OpenSSL (cast to `c_uint`/`size_t`/`u32`) without first comparing it against the length of the `&mut [u8]` slice that was handed to the closure. A buggy or attacker-influenced closure can return a length larger than the slice, causing OpenSSL to read past the buffer and serialize ad

by Provallyupdated 2026-06-12Apache-2.0
1.2K0 direct1.2K via packs
downloads
84quality
All matching rules loaded.