Openssl
This hub aggregates every CVE we track for Openssl, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
314
CVEs tracked
22
Critical
102
High
1
In CISA KEV
Severity distribution
MEDIUM172HIGH102CRITICAL22LOW18
Monthly trend
1
1
1
0
1
2
0
1
1
0
1
0
5
0
0
0
12
0
1
7
0
18
1
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Openssl.
- CVE-2026-54876Client-Side Memory Leak in OCSP Response Checking7.5
- CVE-2026-45784rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers7.1
- CVE-2026-45447Heap Use-After-Free in the PKCS7_verify() Function8.8
- CVE-2026-45446Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes4.8
- CVE-2026-45445AES-OCB IV Ignored on EVP_Cipher() Path7.5
- CVE-2026-42771Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email()6.2
- CVE-2026-42770FFC-DH Peer Validation Uses Attacker-Supplied q3.7
- CVE-2026-42768Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()3.7
- CVE-2026-42769Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate5.3
- CVE-2026-42767NULL Pointer Dereference in CRMF EncryptedValue Decryption5.9
- CVE-2026-42766Possible NULL Dereference in Password-Based CMS Decryption5.9
- CVE-2026-42764NULL Pointer Dereference in QUIC Server Initial Packet Handling7.5
- CVE-2026-42765NULL Dereference in Certificate Verification with OCSP Checking7.5
- CVE-2026-35188Double-free When Checking OCSP Stapled Response5.0
- CVE-2026-34183Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler7.5
Product normalization is registry-driven with AI assist and human review. How it works