Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in OpenSSL, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security weaknesses related to OpenSSL, a widely used open-source cryptographic software library developed by the OpenSSL Project. It collects documented vulnerabilities affecting the OpenSSL toolkit, encompassing issues such as memory corruption, logic errors, and protocol implementation flaws, with data covering releases from version 0.9.8 through the latest 3.x series up to the present date. Here, you can track vendor advisories issued by the OpenSSL Security Team, understand the common weakness enumeration classifications for cryptographic failures, and look up a specific product's vulnerability history to assess patch availability and exposure windows. The repository serves as a centralized reference for security researchers and system administrators to identify risk patterns across different OpenSSL versions. By consolidating these records, the page facilitates a comprehensive view of how specific code paths have been compromised over time. Users can analyze the progression of security patches and correlate findings with industry-wide threat intelligence. This resource does not replace official vendor guidance but provides a structured historical context for OpenSSL security incidents. It is designed to aid in risk management decisions by highlighting recurring vulnerability types and their remediation status. All information presented is derived from public security advisories and CVE assignments, ensuring an accurate and transparent overview of the project's security landscape without speculative analysis or third-party interpretations.

Vendor: OpenSSL

CVE IDTitleCVSSSeverityPublished
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function CWE-416--2026-06-09
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes CWE-325--2026-06-09
CVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() Path CWE-325--2026-06-09
CVE-2026-42771 Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() CWE-125--2026-06-09
CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q CWE-325--2026-06-09
CVE-2026-42769 Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate CWE-295--2026-06-09
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() CWE-514--2026-06-09
CVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue Decryption CWE-476--2026-06-09
CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption CWE-476--2026-06-09
CVE-2026-42765 NULL Dereference in Certificate Verification with OCSP Checking CWE-476--2026-06-09
CVE-2026-42764 NULL Pointer Dereference in QUIC Server Initial Packet Handling CWE-476--2026-06-09
CVE-2026-34183 Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler CWE-1325--2026-06-09
CVE-2026-35188 Double-free When Checking OCSP Stapled Response CWE-415--2026-06-09
CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages CWE-354--2026-06-09
CVE-2026-34181 PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys CWE-354--2026-06-09
CVE-2026-34180 Heap Buffer Over-read in ASN.1 Content Parsing CWE-125--2026-06-09
CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption CWE-125--2026-06-09
CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion CWE-787--2026-06-09
CVE-2026-31790 Incorrect Failure Handling in RSA KEM RSASVE Encapsulation CWE-754 7.5AIHighAI2026-04-07
CVE-2026-31789 Heap Buffer Overflow in Hexadecimal Conversion CWE-787 9.8AICriticalAI2026-04-07
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28387 Potential Use-after-free in DANE Client Code CWE-416 9.8AICriticalAI2026-04-07
CVE-2026-28386 Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 Support CWE-125 7.5AIHighAI2026-04-07
CVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group CWE-757 5.3 -2026-03-13
CVE-2026-22796 ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function CWE-754 7.5AIHighAI2026-01-27
CVE-2026-22795 Missing ASN1_TYPE validation in PKCS#12 parsing CWE-754 7.5AIHighAI2026-01-27
CVE-2025-69421 NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function CWE-476 6.5AIMediumAI2026-01-27
CVE-2025-69420 Missing ASN1_TYPE validation in TS_RESP_verify_response() function CWE-754 6.2AIMediumAI2026-01-27

All 122 known CVE vulnerabilities affecting OpenSSL with full Chinese analysis, references, and POCs where available.