Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 118

Browse all 118 CVE security advisories affecting OpenSSL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenSSL is an open-source toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, primarily used to encrypt network traffic for web servers, email systems, and other internet services. Its widespread adoption makes it a critical infrastructure component, yet its complexity has historically led to numerous vulnerabilities. Common flaw classes include buffer overflows, memory corruption issues, and logic errors that can facilitate remote code execution or denial of service attacks. Notable incidents, such as the Heartbleed bug, exposed sensitive memory data, highlighting risks associated with complex cryptographic implementations. With approximately 99 recorded CVEs, the project emphasizes rigorous code auditing and timely patching to mitigate these risks. Developers must maintain strict version control and apply updates promptly to ensure secure communications, as unpatched instances remain vulnerable to exploitation by malicious actors seeking to intercept or manipulate data in transit.

Found 117 results / 118Clear Filters
Low2026-08-05
x509: fix OCSP BasicResponse leak in in-verify check · openssl/openssl@d8c5104 · GitHub
Low2026-08-05
x509: fix OCSP BasicResponse leak in in-verify check · openssl/openssl@155b5fe · GitHub
LowCVE-2023-548762026-08-05
OpenSSL OCSP响应检查内存泄漏漏洞(CVE-2023-54876)安全公告
HighCVE-2026-581012026-07-14
CVE-2026-58101: OpenSSL X509v3扩展空指针解引用漏洞分析
High2026-07-14
OpenSSL x509_ext堆溢出漏洞修复分析
CriticalCVE-2026-92652026-06-20
CVE-2026-9265 OpenSSL PKCS12堆溢出漏洞及修复
HighCVE-2020-141822026-06-13
Reject potentially forged encrypted CMS AuthEnvelopedData messages · openssl/openssl@03c1f4d · GitHub
High2026-06-13
cms: kek_unwrap_key: Fix out-of-bounds read in check-byte validation · openssl/openssl@05b0663 · GitHub
High2026-06-13
Avoid length truncation in ASN1_STRING_set · openssl/openssl@1c6908e · GitHub
High2026-06-13
Fix handling of empty-ciphertext messages in AES-GCM-SIV and AES-SIV · openssl/openssl@25b32cd · GitHub
Critical2026-06-13
Apply the buffered IV on the AES-OCB EVP_Cipher() path · openssl/openssl@323f0b6 · GitHub
MediumCVE-2024-351882026-06-13
Fix Double-free When Checking OCSP Stapled Response · openssl/openssl@131145d · GitHub
High2026-06-13
Fix NULL Dereference in Certificate Verification with OCSP Checking · openssl/openssl@14340b7 · GitHub
HighCVE-2020-30782026-06-13
cms: kek_unwrap_key: Fix out-of-bounds read in check-byte validation · openssl/openssl@3d8d5bc · GitHub
High2026-06-13
Fix possible use-after-free in OpenSSL PKCS7_verify() · openssl/openssl@3aad5eb · GitHub
High2026-06-13
Match the local q DHX parameter against the peer's q · openssl/openssl@3ddbb7a · GitHub
High2026-06-13
Match the local q DHX parameter against the peer's q · openssl/openssl@3da5a51 · GitHub
High2026-06-13
QUIC stack must limit the number of PATH_CHALLENGE frames processed i… · openssl/openssl@5b306ef · GitHub
CriticalCVE-2026-341822026-06-13
Reject potentially forged encrypted CMS AuthEnvelopedData messages · openssl/openssl@439ed7d · GitHub
High2026-06-13
Use the correct issuer when validating rootCAKeyUpdate · openssl/openssl@54d0989 · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with OpenSSL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.