Where
-Infinity
0

oss-secOpenSSL "HollowByte" DoS via attacker-controlled memory allocation size in glibc

OpenSSL OpenSSLOpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability

Risk 54
First published (updated )
Advisory
ZDI-26-426

OpenSSL OpenSSLZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability

Risk 54
First published (updated )

OpenSSL Crypt::OpenSSL::X509Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts

Risk 69
Severity
9.1
First published (updated )

OpenSSL Crypt::OpenSSL::X509Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

libssh libssh (OpenSSL backend AES-GCM)A flaw was found in libssh builds using the OpenSSL backend for AES-GCM. In the decrypt path in src/…

Risk 19
Severity
4
First published (updated )

oss-secpandemic of incomplete error handling in the OpenSSL ecosystem

First published (updated )

OpenSSL OpenSSLHMAC zero-length tag forgery in EVP_DigestVerifyFinal

Risk 43
Severity
2.1
First published (updated )

OpenSSL ParseCRL_ExtensionsCRL critical extension bypass in ParseCRL_Extensions

Risk 27
Severity
1
First published (updated )

OpenSSL OpenSSLOut-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation

Risk 43
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLUn-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation

Risk 43
Severity
8.2
First published (updated )

OpenSSL OpenSSLPartial-chain verification accepts untrusted intermediate as trust anchor

Risk 38
Severity
6
First published (updated )

oss-secCommon PKCS#7 / CMS parsing issues in OpenSSL, WolfSSL, Bouncy Castle, & GnuPG

oss-secCommon PKCS#7 / CMS parsing issues in OpenSSL, WolfSSL, Bouncy Castle, & GnuPG

oss-secProposal: Add separate oss-security-vulnerability-ports mailing list (for AI vulnpocalypse)

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL PKCS#7 CVE-2026-45447

First published (updated )
Social
reddit

OpenSSL OpenSSLPossible Out of Bounds Read in X509_VERIFY_PARAM_set1_email()

Risk 37
Severity
6.2
First published (updated )

OpenSSL OpenSSLNULL Dereference in Certificate Verification with OCSP Checking

Risk 45
Severity
7.5
First published (updated )

OpenSSL OpenSSLDouble-free When Checking OCSP Stapled Response

Risk 41
Severity
5
First published (updated )

oss-secOpenSSL Security Advisory

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

TychonTychon is vulnerable to privilege escalation due to OPENSSLDIR location

Risk 56
Severity
7.4
First published (updated )

OpenSSL OpenSSLHeap Use-After-Free in the PKCS7_verify() Function

Risk 84
Severity
8.8
First published (updated )

OpenSSL OpenSSLUse After Free

Risk 33
Severity
7
First published (updated )

OpenSSL OpenSSLIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes

Risk 34
Severity
4.8
First published (updated )

OpenSSL OpenSSLIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes Incorrect Tag Processi…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLFFC-DH Peer Validation Uses Attacker-Supplied q

Risk 21
Severity
3.7
First published (updated )

OpenSSL OpenSSLAES-OCB IV Ignored on EVP_Cipher() Path

Risk 46
Severity
7.5
First published (updated )

OpenSSL OpenSSLFFC-DH Peer Validation Uses Attacker-Supplied q (CVE-2026-42770) Severity: Low Issue summary: When …

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLAES-OCB IV Ignored on EVP_Cipher() Path AES-OCB IV Ignored on EVP_Cipher() Path (CVE-2026-45445) Se…

Risk 19
Severity
4
First published (updated )

OpenSSL OpenSSLTrust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate

Risk 34
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203