OpenSSL_jll
JLSEC-2026-277High 7.5UpstreamIssue summary: Applications using RSASVE key encapsulation to establish a secret encrypti…JLSEC-2026-276Critical 9.8UpstreamIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string…JLSEC-2026-275High 7.5UpstreamNo summary availableJLSEC-2026-274High 7.5UpstreamIssue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeReci…JLSEC-2026-273High 7.5UpstreamNo summary availableJLSEC-2026-272High 8.1UpstreamNo summary availableJLSEC-2026-271Medium 6.5UpstreamIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key…JLSEC-2026-270Medium 5.3UpstreamIssue summary: A type confusion vulnerability exists in the signature verification of sig…JLSEC-2026-269Medium 5.5UpstreamIssue summary: An invalid or NULL pointer dereference can happen in an application proces…JLSEC-2026-265High 7.5UpstreamIssue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference…JLSEC-2026-264High 7.5UpstreamIssue summary: A type confusion vulnerability exists in the TimeStamp Response verificati…JLSEC-2026-263High 7.4UpstreamIssue summary: Calling `PKCS12_get_friendlyname()` function on a maliciously crafted PKCS…JLSEC-2026-262Medium 4.0UpstreamIssue summary: When using the low-level OCB API directly with AES-NI or<br>other...JLSEC-2026-261Medium 4.7UpstreamIssue summary: Writing large, newline-free data into a BIO chain using the line-buffering…JLSEC-2026-260Medium 5.9UpstreamIssue summary: A TLS 1.3 connection using certificate compression can be forced to alloca…JLSEC-2026-258Medium 5.5UpstreamIssue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB…JLSEC-2026-257Medium 5.9UpstreamIssue summary: If an application using the `SSL_CIPHER_find()` function in a QUIC protoco…JLSEC-2026-256High 8.8UpstreamIssue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parame…JLSEC-2026-255Medium 6.1UpstreamIssue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigge…JLSEC-2026-268Medium 5.9UpstreamIssue summary: An application using the OpenSSL HTTP client API functions may trigger an.…JLSEC-2026-267Medium 6.5UpstreamIssue summary: A timing side-channel which could potentially allow remote recovery of the…JLSEC-2026-266High 7.5UpstreamNo summary availableJLSEC-2026-259Medium 6.5UpstreamIssue summary: Use of -addreject option with the openssl x509 application adds a trusted …JLSEC-2026-248Medium 4.1UpstreamIssue summary: A timing side-channel which could potentially allow recovering the private…JLSEC-2026-251High 7.5UpstreamIssue summary: Calling the OpenSSL API function `SSL_free_buffers` may cause memory to be…JLSEC-2026-254Medium 4.3UpstreamIssue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit v…JLSEC-2026-253High 7.5UpstreamIssue summary: Applications performing certificate name checks (e.g., TLS clients checkin…JLSEC-2026-252Critical 9.1UpstreamIssue summary: Calling the OpenSSL API function `SSL_select_next_proto` with an empty sup…JLSEC-2026-250Medium 5.3UpstreamIssue summary: Checking excessively long DSA keys or parameters may be very slow.JLSEC-2026-246Medium 5.9UpstreamIssue summary: Checking excessively long invalid RSA public keys may take a long time.JLSEC-2026-249Medium 5.9UpstreamIssue summary: Some non-default TLS server configurations can cause unbounded memory grow…JLSEC-2026-247Medium 5.5UpstreamNull pointer dereference in PKCS12 parsingJLSEC-2026-245Medium 6.5UpstreamIssue summary: The POLY1305 MAC (message authentication code) implementation contains a b…JLSEC-2026-244Medium 5.3UpstreamIssue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.…JLSEC-2026-243High 7.5UpstreamIssue summary: A bug has been identified in the processing of key and initialisation vect…JLSEC-2026-242High 7.8UpstreamIssue summary: The POLY1305 MAC (message authentication code) implementation contains a b…JLSEC-2026-241Medium 5.3UpstreamIssue summary: Checking excessively long DH keys or parameters may be very slow.JLSEC-2026-240Medium 5.3UpstreamIssue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore …JLSEC-2026-239Medium 6.5UpstreamIssue summary: Processing some specially crafted ASN.1 object identifiers or data contain…JLSEC-2026-238Medium 5.9UpstreamIssue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform conta…JLSEC-2026-237Medium 5.3UpstreamThe function `X509_VERIFY_PARAM_add0_policy()` is documented to implicitly enable the cer…JLSEC-2026-236Medium 5.3UpstreamApplications that use a non-default option when verifying certificates may be vulnerable …JLSEC-2026-235High 7.5UpstreamA security vulnerability has been identified in all supported versionsJLSEC-2026-234High 7.4UpstreamVulnerable OpenSSL included in cryptography wheelsJLSEC-2026-233High 7.5Upstreamopenssl-src vulnerable to Use-after-free following `BIO_new_NDEF`JLSEC-2026-232High 7.5Upstreamopenssl-src contains Double free after calling `PEM_read_bio_ex`JLSEC-2026-231Medium 5.9Upstreamopenssl-src subject to Timing Oracle in RSA DecryptionJLSEC-2026-230Medium 5.3UpstreamAES OCB fails to encrypt some bytesJLSEC-2026-229High 7.3UpstreamIn addition to the `c_rehash` shell command injection identified in CVE-2022-1292, furthe…JLSEC-2026-228High 7.3UpstreamThe `c_rehash` script does not properly sanitise shell metacharacters to prevent command …JLSEC-2026-227High 7.5Upstreamopenssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificatesJLSEC-2026-226Medium 5.9UpstreamThere is a carry propagation bug in the MIPS32 and MIPS64 squaring procedureJLSEC-2026-225High 7.4UpstreamRead buffer overruns processing ASN.1 stringsJLSEC-2026-224Critical 9.8UpstreamSM2 Decryption Buffer OverflowJLSEC-2026-223Medium 5.9Upstreamopenssl-src NULL pointer Dereference in `signature_algorithms` processingJLSEC-2026-222Medium 5.9UpstreamInteger Overflow in openssl-srcJLSEC-2026-221High 7.5UpstreamInteger Overflow in openssl-srcJLSEC-2026-220Medium 5.9UpstreamThe X.509 GeneralName type is a generic type for representing different types of namesJLSEC-2026-219High 7.5UpstreamNull pointer deference in openssl-srcJLSEC-2026-216Medium 5.3UpstreamThere is an overflow bug in the `x64_64` Montgomery squaring procedure used in exponentia…JLSEC-2026-218Low 3.7UpstreamIn situations where an attacker receives automated notification of the success or failure…JLSEC-2026-215Medium 5.3UpstreamOpenSSL 1.1.1 introduced a rewritten random number generator (RNG)JLSEC-2026-214Medium 4.7UpstreamNormally in OpenSSL EC groups always have a co-factor present and this is used in side ch…JLSEC-2026-217Low 3.3UpstreamOpenSSL has internal defaults for a directory tree where it can find a configuration file…