CVE-2026-14456
- EPSS 0.47%
- Veröffentlicht 13.08.2026 13:55:52
- Zuletzt bearbeitet 13.08.2026 18:17:18
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer ...
CVE-2026-54876
- EPSS 0.26%
- Veröffentlicht 05.08.2026 13:59:36
- Zuletzt bearbeitet 05.08.2026 20:17:10
Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker-tunable amou...
CVE-2026-69247
- EPSS 0.18%
- Veröffentlicht 03.08.2026 21:16:32
- Zuletzt bearbeitet 04.08.2026 15:16:43
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encry...
CVE-2026-45446
- EPSS 0.37%
- Veröffentlicht 09.06.2026 16:03:32
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can for...
CVE-2026-45447
- EPSS 5.24%
- Veröffentlicht 09.06.2026 16:03:32
- Zuletzt bearbeitet 17.08.2026 12:18:44
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execu...
CVE-2026-45445
- EPSS 0.6%
- Veröffentlicht 09.06.2026 16:03:31
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the same key us...
CVE-2026-42771
- EPSS 0.22%
- Veröffentlicht 09.06.2026 16:03:30
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen. Impact summary: This out of bounds read will not direc...
CVE-2026-42770
- EPSS 0.47%
- Veröffentlicht 09.06.2026 16:03:29
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parame...
CVE-2026-42768
- EPSS 0.58%
- Veröffentlicht 09.06.2026 16:03:28
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output. Impact summary: The Bleichen...
CVE-2026-42769
- EPSS 0.4%
- Veröffentlicht 09.06.2026 16:03:28
- Zuletzt bearbeitet 23.07.2026 08:10:00
Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credenti...