FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

RusTLS FFI -- plaintext TLS handshake vulnerability

Affected packages
rustls-ffi < 0.15.4

Details

VuXML ID ff969b25-b97b-11f1-b09d-8447094a420f
Discovery 2026-09-26
Entry 2026-09-26

The RusTLS project reports:

TLS 1.3 handshake message processing could allow a broken peer to send plaintext handshake messages where an encrypted one is expected without rustls rejecting the connection

References

URL https://github.com/rustls/rustls-ffi/releases/tag/v0.15.4
URL https://github.com/rustls/rustls/security/advisories/GHSA-2mjx-qc3c-rqvc