Vulnerability Description
The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version 0.9.10 fixes the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rustcrypto | Rsa | < 0.9.10 |
Related Weaknesses (CWE)
References
- https://github.com/RustCrypto/RSA/commit/2926c91bef7cb14a7ccd42220a698cf4b1b692fPatch
- https://github.com/RustCrypto/RSA/security/advisories/GHSA-9c48-w39g-hm26Vendor Advisory
FAQ
What is CVE-2026-21895?
CVE-2026-21895 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one o...
How severe is CVE-2026-21895?
CVE-2026-21895 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-21895?
Check the references section above for vendor advisories and patch information. Affected products include: Rustcrypto Rsa.