Known Vulnerabilities for products from Openssl

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Openssl".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-84964 json Not Provided 2026-09-03 2026-09-03
CVE-2026-81717 json Not Provided 2026-08-27 2026-08-27
CVE-2026-81716 json Not Provided 2026-08-27 2026-08-27
CVE-2026-81715 json Not Provided 2026-08-27 2026-08-28
CVE-2026-81714 json Not Provided 2026-08-27 2026-08-27
CVE-2026-81705 json Not Provided 2026-08-27 2026-08-27
CVE-2026-81697 json Not Provided 2026-08-27 2026-08-31
CVE-2026-81694 json Not Provided 2026-08-27 2026-08-28
CVE-2026-81692 json Not Provided 2026-08-27 2026-08-31
CVE-2026-81690 json Not Provided 2026-08-27 2026-08-27
CVE-2026-75803 json Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the sup... Not Provided 2026-08-25 2026-09-11
CVE-2026-63076 json Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NUL... Not Provided 2026-08-25 2026-09-11
CVE-2026-63075 json Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowle... Not Provided 2026-08-25 2026-09-11
CVE-2026-63074 json Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP me... Not Provided 2026-08-25 2026-09-11
CVE-2026-63073 json Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format... Not Provided 2026-08-25 2026-09-11
CVE-2026-63072 json Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AE... Not Provided 2026-08-25 2026-09-11
CVE-2026-54874 json Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more ... Not Provided 2026-08-25 2026-09-11
CVE-2026-45447 json Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature ver... Not Provided 2026-06-09 2026-09-11
CVE-2026-45446 json Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Addi... Not Provided 2026-06-09 2026-07-23
CVE-2026-45445 json Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the applicat... Not Provided 2026-06-09 2026-07-23

Known software with vulnerabilities from Openssl

Type Vendor Product Version
ApplicationOpensslFips Object Module-
ApplicationOpensslOpenssl-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report