Known Vulnerabilities for Openssl by Redhat

Listed below are 9 of the newest known vulnerabilities associated with "Openssl" by "Redhat".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-93964 json A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertifi... Not Provided 2026-09-20 2026-09-22
CVE-2026-93302 json MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that ... Not Provided 2026-09-27 2026-09-29
CVE-2026-92939 json vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The ... Not Provided 2026-09-17 2026-09-17
CVE-2026-91769 json PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, ... Not Provided 2026-09-25 2026-09-28
CVE-2026-91767 json php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS serv... Not Provided 2026-09-25 2026-09-28
CVE-2026-90439 json NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versio... Not Provided 2026-09-15 2026-09-16
CVE-2026-89281 json The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability with... Not Provided 2026-09-22 2026-09-23
CVE-2026-84975 json PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS ba... Not Provided 2026-09-18 2026-09-24
CVE-2026-84964 json A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS e... Not Provided 2026-09-03 2026-09-03
CVE-2026-84784 json Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check... Not Provided 2026-09-29 2026-09-29

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationRedhatOpenssl0.9.7a-2
ApplicationRedhatOpenssl0.9.6b-3
ApplicationRedhatOpenssl0.9.6-15
ApplicationRedhatOpenssl-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report