Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 147

All 147 CVE vulnerabilities found in OpenSSL, with AI-generated Chinese analysis, references, and POCs.

This section aggregates security vulnerabilities affecting OpenSSL, an open-source cryptographic library widely deployed in internet infrastructure. The page collects historical and current advisories related to cryptographic implementations, focusing on memory corruption, protocol flaws, and algorithmic weaknesses within the library. Readers can use this resource to track the vendor’s advisory history, analyze specific weakness classes, or review the complete vulnerability timeline for this product.

Vendor: OpenSSL

CVE ID Title CVSS Severity Published
CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog CWE-770 - - 2026-09-29
CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use CWE-416 - - 2026-09-29
CVE-2026-84782 DTLS Retransmits Handshake Messages From a Stale Buffer Offset CWE-125 - - 2026-09-29
CVE-2026-77696 Timing Side-Channel in SM2 Signature Generation CWE-208 - - 2026-09-29
CVE-2026-75806 Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS CWE-1284 - - 2026-09-29
CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling CWE-476 - - 2026-09-29
CVE-2026-75804 QUIC Connection-Level Flow Control is Not Enforced for Streams CWE-770 - - 2026-09-29
CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake CWE-787 - - 2026-09-29
CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V CWE-208 - - 2026-09-29
CVE-2026-54873 QUIC STREAM Fragment Metadata DoS CWE-770 - - 2026-09-29
CVE-2026-54872 Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves CWE-208 - - 2026-09-29
CVE-2026-42772 Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC CWE-407 - - 2026-09-29
CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted CWE-440 - - 2026-09-29
CVE-2026-35189 Excessive Memory Allocation in Relative CRLDP Processing CWE-770 - - 2026-09-29
CVE-2026-75803 AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() CWE-354 - - 2026-08-25
CVE-2026-63076 Invalid Pointer Dereference in CMP Server via Crafted protectionAlg CWE-476 - - 2026-08-25
CVE-2026-63075 QUIC ACK-only Packet Retention Can Cause Memory Exhaustion CWE-770 - - 2026-08-25
CVE-2026-63074 CMP Indefinite Cache Growth of ExtraCerts CWE-770 - - 2026-08-25
CVE-2026-63073 Untrusted Sender DN Used as Format String in CMP Response Validation CWE-134 - - 2026-08-25
CVE-2026-63072 Heap Buffer Overflow in CMS Key Unwrapping CWE-787 - - 2026-08-25
CVE-2026-54874 Excessive Memory Use Buffering DTLS Records for a Future Epoch CWE-405 - - 2026-08-25
CVE-2026-18798 QUIC Server May Trigger Double Free When Processing INITIAL Packet CWE-415 - - 2026-08-25
CVE-2026-14457 RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate CWE-476 - - 2026-08-25
CVE-2026-14456 Unbounded Memory Growth in QUIC Server Incoming Channel Queue CWE-770 - - 2026-08-13
CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking CWE-401 - - 2026-08-05
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function CWE-416 - - 2026-06-09
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes CWE-325 - - 2026-06-09
CVE-2026-42771 Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() CWE-125 - - 2026-06-09
CVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() Path CWE-325 - - 2026-06-09
CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q CWE-325 - - 2026-06-09

All 147 known CVE vulnerabilities affecting OpenSSL with full Chinese analysis, references, and POCs where available.