OpenSSL bug exposed up to 255 bytes of client heap and existed since 2011

CVE-2024-5535: `SSL_select_next_proto` buffer overread

Third-Party Audit of Rustls

TLS performance: rustls versus OpenSSL

TLS bulk performance: rustls versus OpenSSL

Measuring test coverage of Rust libraries

OpenSSL ECC binpoly denial of service