OpenSSL

OpenSSL

326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 29.09.2026 16:17:08
  • Zuletzt bearbeitet 08.10.2026 01:19:29

Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-l...

  • EPSS 0.27%
  • Veröffentlicht 29.09.2026 16:17:07
  • Zuletzt bearbeitet 08.10.2026 01:01:54

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to signif...

  • EPSS 0.36%
  • Veröffentlicht 29.09.2026 16:17:07
  • Zuletzt bearbeitet 08.10.2026 01:02:06

Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amp...

  • EPSS 0.33%
  • Veröffentlicht 29.09.2026 16:17:07
  • Zuletzt bearbeitet 08.10.2026 01:18:57

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received...

  • EPSS 0.12%
  • Veröffentlicht 25.08.2026 13:19:29
  • Zuletzt bearbeitet 11.09.2026 21:17:17

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications ...

  • EPSS 0.61%
  • Veröffentlicht 25.08.2026 13:19:26
  • Zuletzt bearbeitet 11.09.2026 21:16:34

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap wr...

  • EPSS 0.41%
  • Veröffentlicht 25.08.2026 13:19:26
  • Zuletzt bearbeitet 11.09.2026 21:16:45

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces ...

  • EPSS 0.49%
  • Veröffentlicht 25.08.2026 13:19:26
  • Zuletzt bearbeitet 11.09.2026 21:16:58

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache...

  • EPSS 0.48%
  • Veröffentlicht 25.08.2026 13:19:26
  • Zuletzt bearbeitet 11.09.2026 21:17:05

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summ...

  • EPSS 1.33%
  • Veröffentlicht 25.08.2026 13:19:26
  • Zuletzt bearbeitet 11.09.2026 21:17:12

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type...