Rustls has fixed a medium-severity TLS 1.3 protocol-handling flaw, tracked as RUSTSEC-2026-0285 and GHSA-2mjx-qc3c-rqvc, that accepted handshake messages crossing encryption-level boundaries if they followed a key-changing message in the same TLS record. This could allow, for example, an unencrypted EncryptedExtensions message to be accepted alongside ServerHello, contrary to RFC 8446 section 5.1.
The issue affects Rustls releases from 0.23.13 through versions before 0.23.45; versions earlier than 0.23.13 are unaffected. Rustls 0.23.45 remediates the defect. A network-position attacker cannot alter or complete the authenticated handshake because transcript authentication remains intact, but a peer could send handshake content in plaintext when it should have been encrypted without the connection being rejected. OpenSSL and BoringSSL are not affected; the flaw is functionally equivalent to Go advisory GO-2026-4340 / CVE-2025-61730.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Rustls released version 0.23.45 as the patched version and issued vulnerability advisory GHSA-2mjx-qc3c-rqvc, rated medium severity with CVSS 5.3. The issue is functionally equivalent to GO-2026-4340/CVE-2025-61730; versions before 0.23.13 are listed as unaffected.
Rustls fixed the TLS 1.3 protocol-handling issue in its source code. The flaw could permit plaintext handshake messages, such as EncryptedExtensions, to be accepted where encryption was required.
Rustls version 0.23.13 was released with logic that could accept TLS 1.3 handshake messages crossing encryption-level boundaries when following a key-changing message in the same TLS record.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.