Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 142

Browse all 142 CVE security advisories affecting OpenSSL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenSSL is an open-source toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, primarily used to encrypt network traffic for web servers, email systems, and other internet services. Its widespread adoption makes it a critical infrastructure component, yet its complexity has historically led to numerous vulnerabilities. Common flaw classes include buffer overflows, memory corruption issues, and logic errors that can facilitate remote code execution or denial of service attacks. Notable incidents, such as the Heartbleed bug, exposed sensitive memory data, highlighting risks associated with complex cryptographic implementations. With approximately 99 recorded CVEs, the project emphasizes rigorous code auditing and timely patching to mitigate these risks. Developers must maintain strict version control and apply updates promptly to ensure secure communications, as unpatched instances remain vulnerable to exploitation by malicious actors seeking to intercept or manipulate data in transit.

CVE ID Title CVSS Severity Published
CVE-2026-42769 Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate — OpenSSL CWE-295 - - 2026-06-09
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() — OpenSSL CWE-514 - - 2026-06-09
CVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue Decryption — OpenSSL CWE-476 - - 2026-06-09
CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption — OpenSSL CWE-476 - - 2026-06-09
CVE-2026-42765 NULL Dereference in Certificate Verification with OCSP Checking — OpenSSL CWE-476 - - 2026-06-09
CVE-2026-42764 NULL Pointer Dereference in QUIC Server Initial Packet Handling — OpenSSL CWE-476 - - 2026-06-09
CVE-2026-35188 Double-free When Checking OCSP Stapled Response — OpenSSL CWE-415 - - 2026-06-09
CVE-2026-34183 Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler — OpenSSL CWE-1325 - - 2026-06-09
CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages — OpenSSL CWE-354 - - 2026-06-09
CVE-2026-34181 PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys — OpenSSL CWE-354 - - 2026-06-09
CVE-2026-34180 Heap Buffer Over-read in ASN.1 Content Parsing — OpenSSL CWE-125 - - 2026-06-09
CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption — OpenSSL CWE-125 - - 2026-06-09
CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion — OpenSSL CWE-787 - - 2026-06-09
CVE-2026-31790 Incorrect Failure Handling in RSA KEM RSASVE Encapsulation — OpenSSL CWE-754 7.5AI High AI 2026-04-07
CVE-2026-31789 Heap Buffer Overflow in Hexadecimal Conversion — OpenSSL CWE-787 9.8AI Critical AI 2026-04-07
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo — OpenSSL CWE-476 7.5AI High AI 2026-04-07
CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo — OpenSSL CWE-476 7.5AI High AI 2026-04-07
CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL — OpenSSL CWE-476 7.5AI High AI 2026-04-07
CVE-2026-28387 Potential Use-after-free in DANE Client Code — OpenSSL CWE-416 9.8AI Critical AI 2026-04-07
CVE-2026-28386 Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 Support — OpenSSL CWE-125 7.5AI High AI 2026-04-07
CVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group — OpenSSL CWE-757 5.3 - 2026-03-13
CVE-2026-22796 ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function — OpenSSL CWE-754 7.5AI High AI 2026-01-27
CVE-2026-22795 Missing ASN1_TYPE validation in PKCS#12 parsing — OpenSSL CWE-754 7.5AI High AI 2026-01-27
CVE-2025-69420 Missing ASN1_TYPE validation in TS_RESP_verify_response() function — OpenSSL CWE-754 6.2AI Medium AI 2026-01-27
CVE-2025-69421 NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function — OpenSSL CWE-476 6.5AI Medium AI 2026-01-27
CVE-2025-69419 Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion — OpenSSL CWE-787 7.8AI High AI 2026-01-27
CVE-2025-69418 Unauthenticated/unencrypted trailing bytes with low-level OCB function calls — OpenSSL CWE-325 9.1AI Critical AI 2026-01-27
CVE-2025-68160 Heap out-of-bounds write in BIO_f_linebuffer on short writes — OpenSSL CWE-787 7.5AI High AI 2026-01-27
CVE-2025-15469 'openssl dgst' one-shot codepath silently truncates inputs >16MB — OpenSSL CWE-347 9.1AI Critical AI 2026-01-27
CVE-2025-66199 TLS 1.3 CompressedCertificate excessive memory allocation — OpenSSL CWE-789 7.5AI High AI 2026-01-27

This page lists every published CVE security advisory associated with OpenSSL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.