Home / CVEs we hold for Openssl CVEs we hold for Openssl Records whose assigning authority named Openssl as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption OpenSSL CVE-2026-75803 AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() OpenSSL CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion OpenSSL CVE-2026-63076 Invalid Pointer Dereference in CMP Server via Crafted protectionAlg OpenSSL CVE-2026-63075 QUIC ACK-only Packet Retention Can Cause Memory Exhaustion OpenSSL CVE-2026-63073 Untrusted Sender DN Used as Format String in CMP Response Validation OpenSSL CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking OpenSSL CVE-2026-54874 Excessive Memory Use Buffering DTLS Records for a Future Epoch OpenSSL CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function OpenSSL CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes OpenSSL CVE-2026-42771 Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() OpenSSL CVE-2026-42769 Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate OpenSSL CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() OpenSSL CVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue Decryption OpenSSL CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption OpenSSL CVE-2026-42765 NULL Dereference in Certificate Verification with OCSP Checking OpenSSL CVE-2026-42764 NULL Pointer Dereference in QUIC Server Initial Packet Handling OpenSSL CVE-2026-34183 Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler OpenSSL CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages OpenSSL CVE-2026-34181 PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys OpenSSL CVE-2026-31790 Incorrect Failure Handling in RSA KEM RSASVE Encapsulation OpenSSL CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo OpenSSL CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo OpenSSL CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL OpenSSL CVE-2026-28386 Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 Support OpenSSL CVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group OpenSSL CVE-2026-22796 ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function OpenSSL CVE-2026-18798 QUIC Server May Trigger Double Free When Processing INITIAL Packet OpenSSL CVE-2026-14457 RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate OpenSSL CVE-2026-14456 Unbounded Memory Growth in QUIC Server Incoming Channel Queue OpenSSL CVE-2025-9232 Out-of-bounds read in HTTP client no_proxy handling OpenSSL CVE-2025-9231 Timing side-channel in SM2 algorithm on 64 bit ARM OpenSSL CVE-2025-9230 Out-of-bounds read & write in RFC 3211 KEK Unwrap OpenSSL CVE-2025-69421 NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function OpenSSL CVE-2025-69420 Missing ASN1_TYPE validation in TS_RESP_verify_response() function OpenSSL CVE-2025-69419 Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion OpenSSL CVE-2025-69418 Unauthenticated/unencrypted trailing bytes with low-level OCB function calls OpenSSL CVE-2025-68160 Heap out-of-bounds write in BIO_f_linebuffer on short writes OpenSSL CVE-2025-66199 TLS 1.3 CompressedCertificate excessive memory allocation OpenSSL CVE-2025-4575 The x509 application adds trusted use instead of rejected use OpenSSL CVE-2025-15469 'openssl dgst' one-shot codepath silently truncates inputs >16MB OpenSSL CVE-2025-15468 NULL dereference in SSL_CIPHER_find() function on unknown cipher ID OpenSSL CVE-2025-15467 Stack buffer overflow in CMS (Auth)EnvelopedData parsing OpenSSL CVE-2025-11187 Improper validation of PBMAC1 parameters in PKCS#12 MAC verification OpenSSL CVE-2024-9143 Low-level invalid GF(2^m) parameters lead to OOB memory access OpenSSL CVE-2024-6119 Possible denial of service in X.509 name checks OpenSSL CVE-2024-4603 Excessive time spent checking DSA keys and parameters OpenSSL CVE-2024-2511 Unbounded memory growth with session handling in TLSv1.3 OpenSSL CVE-2024-13176 Timing side-channel in ECDSA signature computation OpenSSL CVE-2024-12797 RFC7250 handshakes with unauthenticated servers don't abort as expected OpenSSL CVE-2023-6237 Excessive time spent checking invalid RSA public keys OpenSSL CVE-2023-6129 POLY1305 MAC implementation corrupts vector registers on PowerPC OpenSSL CVE-2023-5678 Excessive time spent in DH check / generation with large Q parameter value OpenSSL CVE-2023-4807 POLY1305 MAC implementation corrupts XMM registers on Windows OpenSSL CVE-2023-3817 Excessive time spent checking DH q parameter value OpenSSL CVE-2023-3446 Excessive time spent checking DH keys and parameters OpenSSL CVE-2023-2975 AES-SIV implementation ignores empty associated data entries OpenSSL CVE-2023-2650 Possible DoS translating ASN.1 object identifiers OpenSSL CVE-2023-1255 Input buffer over-read in AES-XTS implementation on 64 bit ARM OpenSSL CVE-2023-0465 Invalid certificate policies in leaf certificates are silently ignored OpenSSL CVE-2023-0464 Excessive Resource Usage Verifying X.509 Policy Constraints OpenSSL CVE-2023-0401 NULL dereference during PKCS7 data verification OpenSSL CVE-2023-0286 X.400 address type confusion in X.509 GeneralName OpenSSL CVE-2023-0216 Invalid pointer dereference in d2i_PKCS7 functions OpenSSL CVE-2022-3786 X.509 Email Address Variable Length Buffer Overflow OpenSSL CVE-2022-3358 Using a Custom Cipher with NID_undef may lead to NULL encryption OpenSSL CVE-2022-2274 RSA implementation bug in AVX512IFMA instructions OpenSSL CVE-2022-1473 Resource leakage when decoding certificates and keys OpenSSL CVE-2022-1434 Incorrect MAC key used in the RC4-MD5 ciphersuite OpenSSL CVE-2022-1343 OCSP_basic_verify may incorrectly verify the response signing certificate OpenSSL CVE-2022-0778 Infinite loop in BN_mod_sqrt() reachable when parsing certificates OpenSSL CVE-2021-4160 BN_mod_exp may produce incorrect results on MIPS OpenSSL CVE-2021-4044 Invalid handling of X509_verify_cert() internal errors in libssl OpenSSL CVE-2021-3712 Read buffer overruns processing ASN.1 strings OpenSSL CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT OpenSSL CVE-2021-3449 NULL pointer deref in signature_algorithms processing OpenSSL CVE-2021-23841 Null pointer deref in X509_issuer_and_serial_hash() OpenSSL CVE-2019-1563 Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey OpenSSL CVE-2018-0739 Constructed ASN.1 types with a recursive definition could exceed the stack OpenSSL CVE-2018-0737 Cache timing vulnerability in RSA Key Generation OpenSSL CVE-2018-0735 Timing attack against ECDSA signature generation OpenSSL CVE-2017-3732 BN_mod_exp may produce incorrect results on x86_64 OpenSSL 132 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.