Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.

Openresty_jll

JLSEC-2026-277High 7.5UpstreamIssue summary: Applications using RSASVE key encapsulation to establish a secret encrypti…JLSEC-2026-276Critical 9.8UpstreamIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string…JLSEC-2026-275High 7.5UpstreamNo summary availableJLSEC-2026-274High 7.5UpstreamIssue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeReci…JLSEC-2026-273High 7.5UpstreamNo summary availableJLSEC-2026-272High 8.1UpstreamNo summary availableJLSEC-2026-271Medium 6.5UpstreamIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key…JLSEC-2026-480Medium 5.5Upstreamzlib before 1.3.2 allows CPU consumption via `crc32_combine64` and `crc32_combine_gen64` …JLSEC-2026-270Medium 5.3UpstreamIssue summary: A type confusion vulnerability exists in the signature verification of sig…JLSEC-2026-269Medium 5.5UpstreamIssue summary: An invalid or NULL pointer dereference can happen in an application proces…JLSEC-2026-265High 7.5UpstreamIssue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference…JLSEC-2026-264High 7.5UpstreamIssue summary: A type confusion vulnerability exists in the TimeStamp Response verificati…JLSEC-2026-263High 7.4UpstreamIssue summary: Calling `PKCS12_get_friendlyname()` function on a maliciously crafted PKCS…JLSEC-2026-262Medium 4.0UpstreamIssue summary: When using the low-level OCB API directly with AES-NI or<br>other...JLSEC-2026-261Medium 4.7UpstreamIssue summary: Writing large, newline-free data into a BIO chain using the line-buffering…JLSEC-2026-256High 8.8UpstreamIssue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parame…JLSEC-2026-266High 7.5UpstreamNo summary availableJLSEC-2026-248Medium 4.1UpstreamIssue summary: A timing side-channel which could potentially allow recovering the private…JLSEC-2026-251High 7.5UpstreamIssue summary: Calling the OpenSSL API function `SSL_free_buffers` may cause memory to be…JLSEC-2026-254Medium 4.3UpstreamIssue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit v…JLSEC-2026-252Critical 9.1UpstreamIssue summary: Calling the OpenSSL API function `SSL_select_next_proto` with an empty sup…JLSEC-2026-249Medium 5.9UpstreamIssue summary: Some non-default TLS server configurations can cause unbounded memory grow…JLSEC-2026-247Medium 5.5UpstreamNull pointer dereference in PKCS12 parsingJLSEC-2026-244Medium 5.3UpstreamIssue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.…JLSEC-2026-479Critical 9.8UpstreamNo summary availableJLSEC-2026-3High 7.5UpstreamThe HTTP/2 protocol allows a denial of service (server resource consumption) because requ…JLSEC-2026-242High 7.8UpstreamIssue summary: The POLY1305 MAC (message authentication code) implementation contains a b…JLSEC-2026-241Medium 5.3UpstreamIssue summary: Checking excessively long DH keys or parameters may be very slow.JLSEC-2026-239Medium 6.5UpstreamIssue summary: Processing some specially crafted ASN.1 object identifiers or data contain…JLSEC-2026-237Medium 5.3UpstreamThe function `X509_VERIFY_PARAM_add0_policy()` is documented to implicitly enable the cer…JLSEC-2026-236Medium 5.3UpstreamApplications that use a non-default option when verifying certificates may be vulnerable …JLSEC-2026-235High 7.5UpstreamA security vulnerability has been identified in all supported versionsJLSEC-2026-234High 7.4UpstreamVulnerable OpenSSL included in cryptography wheelsJLSEC-2026-233High 7.5Upstreamopenssl-src vulnerable to Use-after-free following `BIO_new_NDEF`JLSEC-2026-232High 7.5Upstreamopenssl-src contains Double free after calling `PEM_read_bio_ex`JLSEC-2026-231Medium 5.9Upstreamopenssl-src subject to Timing Oracle in RSA DecryptionJLSEC-2026-478Critical 9.8UpstreamNo summary availableJLSEC-2026-230Medium 5.3UpstreamAES OCB fails to encrypt some bytesJLSEC-2026-229High 7.3UpstreamIn addition to the `c_rehash` shell command injection identified in CVE-2022-1292, furthe…JLSEC-2026-228High 7.3UpstreamThe `c_rehash` script does not properly sanitise shell metacharacters to prevent command …JLSEC-2026-477High 7.5UpstreamNo summary availableJLSEC-2026-227High 7.5Upstreamopenssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificatesJLSEC-2026-226Medium 5.9UpstreamThere is a carry propagation bug in the MIPS32 and MIPS64 squaring procedureJLSEC-2026-225High 7.4UpstreamRead buffer overruns processing ASN.1 stringsJLSEC-2026-222Medium 5.9UpstreamInteger Overflow in openssl-srcJLSEC-2026-221High 7.5UpstreamInteger Overflow in openssl-srcJLSEC-2026-220Medium 5.9UpstreamThe X.509 GeneralName type is a generic type for representing different types of namesJLSEC-2026-177Medium 5.3UpstreamNo summary availableJLSEC-2026-216Medium 5.3UpstreamThere is an overflow bug in the `x64_64` Montgomery squaring procedure used in exponentia…