Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 142

Browse all 142 CVE security advisories affecting OpenSSL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenSSL is an open-source toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, primarily used to encrypt network traffic for web servers, email systems, and other internet services. Its widespread adoption makes it a critical infrastructure component, yet its complexity has historically led to numerous vulnerabilities. Common flaw classes include buffer overflows, memory corruption issues, and logic errors that can facilitate remote code execution or denial of service attacks. Notable incidents, such as the Heartbleed bug, exposed sensitive memory data, highlighting risks associated with complex cryptographic implementations. With approximately 99 recorded CVEs, the project emphasizes rigorous code auditing and timely patching to mitigate these risks. Developers must maintain strict version control and apply updates promptly to ensure secure communications, as unpatched instances remain vulnerable to exploitation by malicious actors seeking to intercept or manipulate data in transit.

Found 141 results / 142 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog — OpenSSL CWE-770 - - 2026-09-29
CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use — OpenSSL CWE-416 - - 2026-09-29
CVE-2026-84782 DTLS Retransmits Handshake Messages From a Stale Buffer Offset — OpenSSL CWE-125 - - 2026-09-29
CVE-2026-77696 Timing Side-Channel in SM2 Signature Generation — OpenSSL CWE-208 - - 2026-09-29
CVE-2026-75806 Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS — OpenSSL CWE-1284 - - 2026-09-29
CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling — OpenSSL CWE-476 - - 2026-09-29
CVE-2026-75804 QUIC Connection-Level Flow Control is Not Enforced for Streams — OpenSSL CWE-770 - - 2026-09-29
CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake — OpenSSL CWE-787 - - 2026-09-29
CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V — OpenSSL CWE-208 - - 2026-09-29
CVE-2026-54873 QUIC STREAM Fragment Metadata DoS — OpenSSL CWE-770 - - 2026-09-29
CVE-2026-54872 Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves — OpenSSL CWE-208 - - 2026-09-29
CVE-2026-42772 Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC — OpenSSL CWE-407 - - 2026-09-29
CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted — OpenSSL CWE-440 - - 2026-09-29
CVE-2026-35189 Excessive Memory Allocation in Relative CRLDP Processing — OpenSSL CWE-770 - - 2026-09-29
CVE-2026-75803 AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() — OpenSSL CWE-354 - - 2026-08-25
CVE-2026-63076 Invalid Pointer Dereference in CMP Server via Crafted protectionAlg — OpenSSL CWE-476 - - 2026-08-25
CVE-2026-63075 QUIC ACK-only Packet Retention Can Cause Memory Exhaustion — OpenSSL CWE-770 - - 2026-08-25
CVE-2026-63074 CMP Indefinite Cache Growth of ExtraCerts — OpenSSL CWE-770 - - 2026-08-25
CVE-2026-63073 Untrusted Sender DN Used as Format String in CMP Response Validation — OpenSSL CWE-134 - - 2026-08-25
CVE-2026-63072 Heap Buffer Overflow in CMS Key Unwrapping — OpenSSL CWE-787 - - 2026-08-25
CVE-2026-54874 Excessive Memory Use Buffering DTLS Records for a Future Epoch — OpenSSL CWE-405 - - 2026-08-25
CVE-2026-18798 QUIC Server May Trigger Double Free When Processing INITIAL Packet — OpenSSL CWE-415 - - 2026-08-25
CVE-2026-14457 RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate — OpenSSL CWE-476 - - 2026-08-25
CVE-2026-14456 Unbounded Memory Growth in QUIC Server Incoming Channel Queue — OpenSSL CWE-770 - - 2026-08-13
CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking — OpenSSL CWE-401 - - 2026-08-05
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function — OpenSSL CWE-416 - - 2026-06-09
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes — OpenSSL CWE-325 - - 2026-06-09
CVE-2026-42771 Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() — OpenSSL CWE-125 - - 2026-06-09
CVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() Path — OpenSSL CWE-325 - - 2026-06-09
CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q — OpenSSL CWE-325 - - 2026-06-09

This page lists every published CVE security advisory associated with OpenSSL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.