Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2026-7383
Issue summary: A signed integer overflow when sizing the destination
buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap
buffer ove…
OpenSSL
1.0.2zq / 1.1.1zh+
HIGH 7.5
CVE-2026-9076
Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)
processes attacker-supplied CMS data, an attacker-chosen stream-mode K…
OpenSSL
1.0.2zq / 1.1.1zh+
HIGH 8.8
CVE-2026-45447EPSS 5%
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.
Impact summa…
OpenSSL
1.0.2zq / 1.1.1zh+
HIGH 7.5
CVE-2026-45445
Issue summary: When an application drives an AES-OCB context through the
public EVP_Cipher() one-shot interface, the application-supplied
initialisat…
OpenSSL
3.0.21 / 3.4.6+
MEDIUM 6.2
CVE-2026-42771
Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an
application to validate a crafted e-mail address, such as during S/MIME
message …
OpenSSL
Patch available
MEDIUM 5.9
CVE-2026-42767
Issue summary: An attacker-controlled CMP (Certificate Management Protocol)
server could trigger a NULL pointer dereference in a CMP client applicati…
OpenSSL
3.0.21 / 3.4.6+
MEDIUM 5.3
CVE-2026-42769
Issue Summary: An error in the callback used to verify the certificate
provided in a Root CA key update Certificate Management Protocol (CMP)
message…
OpenSSL
3.4.6 / 3.5.7+
HIGH 7.5
CVE-2026-42764
Issue summary: Receiving a QUIC initial packet with an invalid token may
trigger a NULL pointer dereference in the OpenSSL QUIC server with
address v…
OpenSSL
3.5.7 / 3.6.3+
HIGH 7.5
CVE-2026-42765
Issue summary: When a partial-chain certificate verification is enabled
together with OCSP response checking for the whole chain, a NULL dereference
…
OpenSSL
3.6.3+
MEDIUM 5.9
CVE-2026-42766
Issue summary: A specially crafted password-encrypted CMS message
can trigger a NULL pointer dereference during CMS decryption.
Impact summary: This…
OpenSSL
1.0.2zq / 1.1.1zh+
HIGH 7.5
CVE-2026-34183
Issue summary: Remote peer may exhaust heap memory of the QUIC
server or client by flooding it with packets containing PATH_CHALLENGE
frames.
Impact…
OpenSSL
3.4.6 / 3.5.7+
MEDIUM 5.0
CVE-2026-35188
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering
a crafted response through the status_request extension, triggering a
d…
OpenSSL
3.6.3+
CRITICAL 9.1
CVE-2026-34182
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform
sufficient input validation on the cipher and tag length fields of
Au…
OpenSSL
3.0.21 / 3.4.6+
HIGH 7.5
CVE-2026-34180
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive
element whose content exceeds 2 gigabytes in length may cause a heap bu…
OpenSSL
1.0.2zq / 1.1.1zh+
HIGH 7.4
CVE-2026-34181
Issue Summary: The PKCS#12 file processing fails to perform sufficient input
validation for files that use Password-Based Message Authentication Code…
OpenSSL
3.4.6 / 3.5.7+
CRITICAL 9.8
CVE-2026-31789
Issue summary: Converting an excessively large OCTET STRING value to
a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.
Impac…
OpenSSL
3.0.20 / 3.3.7+
HIGH 7.5
CVE-2026-28389
Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyAgreeRecipientInfo a NULL pointer dereference can happen.
Impact sum…
OpenSSL
1.0.2zp / 1.1.1zg+
HIGH 7.5
CVE-2026-28390
Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyTransportRecipientInfo a NULL pointer dereference can happen.
Impact…
OpenSSL
1.0.2zp / 1.1.1zg+
HIGH 7.5
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establish
a secret encryption key can send contents of an uninitialized memory buffer t…
OpenSSL
3.0.20 / 3.3.7+
HIGH 8.1
CVE-2026-28387
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA reco…
OpenSSL
1.1.1zg / 3.0.20+
HIGH 7.5
CVE-2026-28386
Issue summary: Applications using AES-CFB128 encryption or decryption on
systems with AVX-512 and VAES support can trigger an out-of-bounds read
of u…
OpenSSL
3.6.2+
HIGH 7.5
CVE-2026-28388
Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
is processed a NULL pointer dereference might happen if the required CR…
OpenSSL
1.0.2zp / 1.1.1zg+
MEDIUM 6.5
CVE-2026-2673
Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected
preferred key exchange group when its key exchange group configuration in…
OpenSSL
3.5.6 / 3.6.2+
MEDIUM 5.5
CVE-2026-22795
Issue summary: An invalid or NULL pointer dereference can happen in
an application processing a malformed PKCS#12 file.
Impact summary: An applicati…
OpenSSL
1.1.1ze / 3.0.19+
MEDIUM 5.3
CVE-2026-22796
Issue summary: A type confusion vulnerability exists in the signature
verification of signed PKCS#7 data where an ASN1_TYPE union member is
accessed …
OpenSSL
1.0.2zn / 1.1.1ze+
HIGH 7.5
CVE-2025-69420
Issue summary: A type confusion vulnerability exists in the TimeStamp Response
verification code where an ASN1_TYPE union member is accessed without …
OpenSSL
1.1.1ze / 3.0.19+
HIGH 7.5
CVE-2025-69421
Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer
dereference in the PKCS12_item_decrypt_d2i_ex() function.
Impact summa…
OpenSSL
1.0.2zn / 3.0.19+
HIGH 7.4
CVE-2025-69419
Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously
crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing
…
OpenSSL
1.1.1ze / 3.0.19+
MEDIUM 5.9
CVE-2025-66199
Issue summary: A TLS 1.3 connection using certificate compression can be
forced to allocate a large buffer before decompression without checking
agai…
OpenSSL
3.3.6 / 3.4.4+
HIGH 8.8
CVE-2025-15467EPSS 48%
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
maliciously crafted AEAD parameters can trigger a stack buffer overflow.
…
OpenSSL
3.0.19 / 3.3.6+