Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 124

All 124 CVE vulnerabilities found in OpenSSL, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the OpenSSL product, focusing on common weakness types and security tags. It compiles a comprehensive list of discovered vulnerabilities affecting this widely used cryptographic library software. The data covers security issues reported over the past ten years, providing a historical perspective on the product’s security landscape. By reviewing this collection, users can effectively track advisories issued by the OpenSSL team and monitor how specific common weakness types have been addressed over time. The aggregated data allows for a deeper understanding of the weakness classes prevalent in this library, helping developers and security analysts identify patterns in defect types. Additionally, readers can look up the vulnerability history of OpenSSL to assess the evolution of its security posture. This resource serves as a reference for understanding the context and frequency of past incidents, supporting informed decision-making for updates and remediation strategies. The information is presented in a neutral, factual manner to facilitate technical analysis without bias. Access to this structured overview aids in maintaining awareness of potential risks associated with the OpenSSL ecosystem. The content is curated to provide clarity on the scope of known issues, ensuring that stakeholders have access to reliable historical data for risk assessment and compliance purposes.

Vendor: OpenSSL

CVE IDTitleCVSSSeverityPublished
CVE-2026-14456 Unbounded Memory Growth in QUIC Server Incoming Channel Queue CWE-770--2026-08-13
CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking CWE-401--2026-08-05
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function CWE-416--2026-06-09
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes CWE-325--2026-06-09
CVE-2026-42771 Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() CWE-125--2026-06-09
CVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() Path CWE-325--2026-06-09
CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q CWE-325--2026-06-09
CVE-2026-42769 Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate CWE-295--2026-06-09
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() CWE-514--2026-06-09
CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption CWE-476--2026-06-09
CVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue Decryption CWE-476--2026-06-09
CVE-2026-42765 NULL Dereference in Certificate Verification with OCSP Checking CWE-476--2026-06-09
CVE-2026-42764 NULL Pointer Dereference in QUIC Server Initial Packet Handling CWE-476--2026-06-09
CVE-2026-35188 Double-free When Checking OCSP Stapled Response CWE-415--2026-06-09
CVE-2026-34183 Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler CWE-1325--2026-06-09
CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages CWE-354--2026-06-09
CVE-2026-34181 PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys CWE-354--2026-06-09
CVE-2026-34180 Heap Buffer Over-read in ASN.1 Content Parsing CWE-125--2026-06-09
CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption CWE-125--2026-06-09
CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion CWE-787--2026-06-09
CVE-2026-31790 Incorrect Failure Handling in RSA KEM RSASVE Encapsulation CWE-754 7.5AIHighAI2026-04-07
CVE-2026-31789 Heap Buffer Overflow in Hexadecimal Conversion CWE-787 9.8AICriticalAI2026-04-07
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL CWE-476 7.5AIHighAI2026-04-07
CVE-2026-28387 Potential Use-after-free in DANE Client Code CWE-416 9.8AICriticalAI2026-04-07
CVE-2026-28386 Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 Support CWE-125 7.5AIHighAI2026-04-07
CVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group CWE-757 5.3 -2026-03-13
CVE-2026-22796 ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function CWE-754 7.5AIHighAI2026-01-27
CVE-2026-22795 Missing ASN1_TYPE validation in PKCS#12 parsing CWE-754 7.5AIHighAI2026-01-27

All 124 known CVE vulnerabilities affecting OpenSSL with full Chinese analysis, references, and POCs where available.