← Back to feed Search feed

OpenSSL vulnerabilities

38 entries matching openssl — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-84975PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTHIGH7.4NVD2026-09-18
CVE-2026-92939vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed.CRITICAL9.444%ileNVD2026-09-17
CVE-2026-90439NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL vMEDIUM6.918%ileNVD2026-09-15
CVE-2026-80229OpenSSL provider use-after-freeHIGH7.558%ileMicrosoft2026-09-08
CVE-2026-78124strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of releaLOW3.79%ileMicrosoft2026-09-08
CVE-2026-80230OpenSSL pinning bypassLOW3.746%ileMicrosoft2026-09-08
CVE-2015-0204OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)=UNKNOWN100%ileOpenStack2026-08-27
CVE-2026-70454rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL ModeHIGH8.09%ileMicrosoft2026-08-11
CVE-2026-54874Excessive Memory Use Buffering DTLS Records for a Future EpochHIGH7.543%ileMicrosoft2026-08-11
CVE-2026-63072Heap Buffer Overflow in CMS Key UnwrappingHIGH7.551%ileMicrosoft2026-08-11
CVE-2026-63075QUIC ACK-only Packet Retention Can Cause Memory ExhaustionHIGH7.541%ileMicrosoft2026-08-11
CVE-2026-63076Invalid Pointer Dereference in CMP Server via Crafted protectionAlgHIGH7.570%ileMicrosoft2026-08-11
CVE-2026-63073Untrusted Sender DN Used as Format String in CMP Response ValidationHIGH7.459%ileMicrosoft2026-08-11
CVE-2026-14663PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartextMEDIUM6.51%ileMicrosoft2026-08-11
CVE-2026-53583libgit2: Inverted IP SubjectAltName Comparison in OpenSSL BackendMEDIUM6.59%ileMicrosoft2026-08-11
CVE-2026-63074CMP Indefinite Cache Growth of ExtraCertsMEDIUM5.942%ileMicrosoft2026-08-11
CVE-2026-59847Libssh: libssh: integrity downgrade via openssl aes-gcm tag verificationMEDIUM5.927%ileMicrosoft2026-07-14
CVE-2026-14355ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PADMEDIUM5.621%ileMicrosoft2026-07-14
CVE-2026-34182CMS AuthEnvelopedData Processing May Accept Forged MessagesCRITICAL9.148%ileMicrosoft2026-06-09
CVE-2026-45447Heap Use-After-Free in the PKCS7_verify() FunctionHIGH8.889%ileMicrosoft2026-06-09
CVE-2026-7383Possible Heap Buffer Overflow in ASN.1 Multibyte String ConversionHIGH8.155%ileMicrosoft2026-06-09
CVE-2026-34180Heap Buffer Over-read in ASN.1 Content ParsingHIGH7.562%ileMicrosoft2026-06-09
CVE-2026-34183Unbounded Memory Growth in the QUIC PATH_CHALLENGE HandlerHIGH7.563%ileMicrosoft2026-06-09
CVE-2026-45445AES-OCB IV Ignored on EVP_Cipher() PathHIGH7.552%ileMicrosoft2026-06-09
CVE-2026-9076Out-of-Bounds Read in CMS Password-Based DecryptionHIGH7.552%ileMicrosoft2026-06-09
CVE-2026-42766Possible NULL Dereference in Password-Based CMS DecryptionMEDIUM5.963%ileMicrosoft2026-06-09
CVE-2026-42767NULL Pointer Dereference in CRMF EncryptedValue DecryptionMEDIUM5.945%ileMicrosoft2026-06-09
CVE-2026-42769Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdateMEDIUM5.334%ileMicrosoft2026-06-09
CVE-2026-45446Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modesMEDIUM4.838%ileMicrosoft2026-06-09
CVE-2026-42768Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()LOW3.746%ileMicrosoft2026-06-09
CVE-2026-42770FFC-DH Peer Validation Uses Attacker-Supplied qLOW3.742%ileMicrosoft2026-06-09
CVE-2026-44662rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-paddingUNKNOWN7%ileMicrosoft2026-05-12
CVE-2025-14575Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loadingUNKNOWN1%ileMicrosoft2026-05-12
CVE-2025-14819OpenSSL partial chain store policy bypassMEDIUM5.353%ileMicrosoft2026-01-13
CVE-2025-9230Out-of-bounds read & write in RFC 3211 KEK UnwrapHIGH7.574%ileMicrosoft2025-09-09
CVE-2025-9232Out-of-bounds read in HTTP client no_proxy handlingMEDIUM5.980%ileMicrosoft2025-09-09
CVE-2025-60018Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certificMEDIUM4.824%ileMicrosoft2025-09-09
CVE-2025-60019Glib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via LOW3.729%ileMicrosoft2025-09-09