OpenSSL

OpenSSL

326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.39%
  • Veröffentlicht 29.09.2026 16:17:12
  • Zuletzt bearbeitet 08.10.2026 01:20:56

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state th...

Medienbericht
  • EPSS 0.23%
  • Veröffentlicht 29.09.2026 16:17:12
  • Zuletzt bearbeitet 08.10.2026 01:21:13

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threa...

  • EPSS 0.4%
  • Veröffentlicht 29.09.2026 16:17:12
  • Zuletzt bearbeitet 08.10.2026 01:21:22

Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame...

  • EPSS 0.22%
  • Veröffentlicht 29.09.2026 16:17:11
  • Zuletzt bearbeitet 08.10.2026 01:20:24

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happe...

Medienbericht
  • EPSS 0.39%
  • Veröffentlicht 29.09.2026 16:17:11
  • Zuletzt bearbeitet 08.10.2026 01:20:33

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: ...

  • EPSS 0.24%
  • Veröffentlicht 29.09.2026 16:17:11
  • Zuletzt bearbeitet 08.10.2026 01:20:41

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, whic...

  • EPSS 0.35%
  • Veröffentlicht 29.09.2026 16:17:10
  • Zuletzt bearbeitet 08.10.2026 01:20:01

Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of...

  • EPSS 0.27%
  • Veröffentlicht 29.09.2026 16:17:09
  • Zuletzt bearbeitet 08.10.2026 01:19:41

Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature a...

  • EPSS 0.26%
  • Veröffentlicht 29.09.2026 16:17:08
  • Zuletzt bearbeitet 08.10.2026 01:19:04

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker ...

  • EPSS 0.46%
  • Veröffentlicht 29.09.2026 16:17:08
  • Zuletzt bearbeitet 08.10.2026 01:19:18

Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memo...