<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Just woke up to 5 vulnerability alerts (4 high severity) of the openSSL Rust crate.]]></title><description><![CDATA[<p>Just woke up to 5 vulnerability alerts (4 high severity) of the openSSL Rust crate. Now I'm even more thankful we've made the switch to rustls in lychee. I've only seen advantages so far. The transition was totally smooth, and now we have faster, more stable and apparently more secure TLS.</p><p>Thank you <span><a href="/user/djc%40hachyderm.io">@<span>djc</span></a></span>, <span><a href="https://infosec.exchange/@ctz">@<span>ctz</span></a></span> et al. for this amazing piece of software!</p><p><a href="https://mastodon.social/tags/rust" rel="tag">#<span>rust</span></a> <a href="https://mastodon.social/tags/openssl" rel="tag">#<span>openssl</span></a> <a href="https://mastodon.social/tags/rustls" rel="tag">#<span>rustls</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://files.mastodon.social/media_attachments/files/116/452/669/678/423/167/original/1a9d827485938605.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/559073bd-a7ef-4218-8c7b-6688ad5027db/just-woke-up-to-5-vulnerability-alerts-4-high-severity-of-the-openssl-rust-crate.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:33:54 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/559073bd-a7ef-4218-8c7b-6688ad5027db.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 23 Apr 2026 06:51:48 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Just woke up to 5 vulnerability alerts (4 high severity) of the openSSL Rust crate. on Thu, 23 Apr 2026 06:58:25 GMT]]></title><description><![CDATA[<p>Here we switched before the last release in February: <a href="https://github.com/lycheeverse/lychee/pull/1928" rel="nofollow noopener"><span>https://</span><span>github.com/lycheeverse/lychee/</span><span>pull/1928</span></a></p><p>It resolved multiple inconsistencies as lychee behaved differently on each target platform as the target platform's openSSL implementation was used. Switching to rustls has resolved multiple long-standing issues and we haven't received any related bug reports since.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/thomas_zahner/statuses/116452721014365246</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/thomas_zahner/statuses/116452721014365246</guid><dc:creator><![CDATA[thomas_zahner@mastodon.social]]></dc:creator><pubDate>Thu, 23 Apr 2026 06:58:25 GMT</pubDate></item></channel></rss>