Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 123

All 123 CVE vulnerabilities found in OpenSSL, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations associated with the OpenSSL cryptographic software library maintained by The OpenSSL Project. It compiles historical security advisories, bug reports, and public disclosures related to critical flaws ranging from memory corruption and buffer overflows to logic errors in protocol implementation, covering vulnerability reports from 2008 through the present day. By examining this comprehensive dataset, security professionals can effectively track the vendor’s historical response patterns and advisory timelines, gain a deeper understanding of the systemic risks inherent in widely deployed encryption infrastructure, and reconstruct the specific vulnerability history of the product to identify recurring themes or regression issues. The collection serves as a reference for analyzing how the maintainers address diverse attack surfaces, including TLS handshake anomalies, certificate validation failures, and side-channel vulnerabilities. Readers can utilize this information to assess the long-term stability of the software, evaluate the effectiveness of past remediation efforts, and benchmark current security postures against established historical trends. This resource does not provide real-time alerting but rather offers a structured view of past incidents to support risk assessment, compliance auditing, and secure configuration planning for systems relying on OpenSSL for data protection and identity verification.

Vendor: OpenSSL

CVE IDTitleCVSSSeverityPublished
CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking CWE-401--2026-08-05
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function CWE-416--2026-06-09
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes CWE-325--2026-06-09
CVE-2026-42771 Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() CWE-125--2026-06-09
CVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() Path CWE-325--2026-06-09
CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q CWE-325--2026-06-09
CVE-2026-42769 Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate CWE-295--2026-06-09
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() CWE-514--2026-06-09
CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption CWE-476--2026-06-09
CVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue Decryption CWE-476--2026-06-09
CVE-2026-42765 NULL Dereference in Certificate Verification with OCSP Checking CWE-476--2026-06-09
CVE-2026-42764 NULL Pointer Dereference in QUIC Server Initial Packet Handling CWE-476--2026-06-09
CVE-2026-35188 Double-free When Checking OCSP Stapled Response CWE-415--2026-06-09
CVE-2026-34183 Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler CWE-1325--2026-06-09
CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages CWE-354--2026-06-09
CVE-2026-34181 PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys CWE-354--2026-06-09
CVE-2026-34180 Heap Buffer Over-read in ASN.1 Content Parsing CWE-125--2026-06-09
CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption CWE-125--2026-06-09
CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion CWE-787--2026-06-09
CVE-2026-31790 Incorrect Failure Handling in RSA KEM RSASVE Encapsulation CWE-754 7.5AIHighAI2026-04-07
CVE-2026-31789 Heap Buffer Overflow in Hexadecimal Conversion CWE-787 9.8AICriticalAI2026-04-07
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28387 Potential Use-after-free in DANE Client Code CWE-416 9.8AICriticalAI2026-04-07
CVE-2026-28386 Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 Support CWE-125 7.5AIHighAI2026-04-07
CVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group CWE-757 5.3 -2026-03-13
CVE-2026-22796 ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function CWE-754 7.5AIHighAI2026-01-27
CVE-2026-22795 Missing ASN1_TYPE validation in PKCS#12 parsing CWE-754 7.5AIHighAI2026-01-27
CVE-2025-69421 NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function CWE-476 6.5AIMediumAI2026-01-27

All 123 known CVE vulnerabilities affecting OpenSSL with full Chinese analysis, references, and POCs where available.