{"schema_version":1,"title":"OpenSSL vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 59 vulnerabilities in OpenSSL: 0 in the last 7 days and 10 in the last 90 days, 5 of them critical and 1 exploited in the wild. The most recent, CVE-2026-90439, was published on 15 September 2026.","url":"https://junglewise.ai/threats/technologies/openssl","json_url":"https://junglewise.ai/threats/technologies/openssl.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openssl","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":21,"all_time":59,"critical":5,"exploited":1,"last_7_days":0,"last_30_days":1,"last_90_days":10,"last_365_days":47},"latest":[{"cve":"CVE-2026-90439","cvss":6.5,"epss":0.0043,"slug":"cve-2026-90439-nginx-plus-and-open-source-http-3-heap-buffer-overflow-in-tls","title":"NGINX Plus and Open Source HTTP/3 heap buffer overflow in TLS handshake","severity":"medium","exploited":false,"published_at":"2026-09-15T15:17:27.023+00:00","url":"https://junglewise.ai/threats/cve-2026-90439-nginx-plus-and-open-source-http-3-heap-buffer-overflow-in-tls"},{"cve":"CVE-2026-75803","cvss":9.1,"epss":0.0022,"slug":"cve-2026-75803-openssl-chacha20-poly1305-and-aes-ocb-authentication-tag-bypass","title":"OpenSSL ChaCha20-Poly1305 and AES-OCB authentication tag bypass","severity":"critical","exploited":false,"published_at":"2026-08-25T13:19:29.57+00:00","url":"https://junglewise.ai/threats/cve-2026-75803-openssl-chacha20-poly1305-and-aes-ocb-authentication-tag-bypass"},{"cve":"CVE-2026-63076","cvss":7.5,"epss":0.0182,"slug":"cve-2026-63076-openssl-cmp-password-protection-verification-null-pointer","title":"OpenSSL CMP password protection verification null pointer dereference","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:26.543+00:00","url":"https://junglewise.ai/threats/cve-2026-63076-openssl-cmp-password-protection-verification-null-pointer"},{"cve":"CVE-2026-63075","cvss":7.5,"epss":0.0078,"slug":"cve-2026-63075-openssl-quic-memory-exhaustion-denial-of-service","title":"OpenSSL QUIC memory exhaustion denial of service","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:26.413+00:00","url":"https://junglewise.ai/threats/cve-2026-63075-openssl-quic-memory-exhaustion-denial-of-service"},{"cve":"CVE-2026-63074","cvss":5.9,"epss":0.0056,"slug":"cve-2026-63074-openssl-cmp-unbounded-certificate-cache-growth","title":"OpenSSL CMP unbounded certificate cache growth","severity":"medium","exploited":false,"published_at":"2026-08-25T13:19:26.283+00:00","url":"https://junglewise.ai/threats/cve-2026-63074-openssl-cmp-unbounded-certificate-cache-growth"},{"cve":"CVE-2026-63073","cvss":9.8,"epss":0.0116,"slug":"cve-2026-63073-openssl-cmp-response-validation-format-string","title":"OpenSSL CMP response validation format string","severity":"critical","exploited":false,"published_at":"2026-08-25T13:19:26.147+00:00","url":"https://junglewise.ai/threats/cve-2026-63073-openssl-cmp-response-validation-format-string"},{"cve":"CVE-2026-63072","cvss":7.5,"epss":0.0101,"slug":"cve-2026-63072-openssl-heap-overflow-in-cms-key-unwrap","title":"OpenSSL heap overflow in CMS key unwrap","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:26.01+00:00","url":"https://junglewise.ai/threats/cve-2026-63072-openssl-heap-overflow-in-cms-key-unwrap"},{"cve":"CVE-2026-54874","cvss":7.5,"epss":0.0131,"slug":"cve-2026-54874-openssl-dtls-memory-exhaustion-in-epoch-buffering","title":"OpenSSL DTLS memory exhaustion in epoch buffering","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:24.033+00:00","url":"https://junglewise.ai/threats/cve-2026-54874-openssl-dtls-memory-exhaustion-in-epoch-buffering"},{"cve":"CVE-2026-18798","cvss":7.5,"epss":0.0154,"slug":"cve-2026-18798-openssl-quic-double-free-in-qrx-object","title":"OpenSSL QUIC double free in QRX object","severity":"high","exploited":false,"published_at":"2026-08-25T13:17:49.813+00:00","url":"https://junglewise.ai/threats/cve-2026-18798-openssl-quic-double-free-in-qrx-object"},{"cve":"CVE-2026-14457","cvss":7.5,"epss":0.0102,"slug":"cve-2026-14457-openssl-null-pointer-dereference-in-rfc7250-raw-public-key","title":"OpenSSL NULL pointer dereference in RFC7250 Raw Public Key handling","severity":"high","exploited":false,"published_at":"2026-08-25T13:17:49.533+00:00","url":"https://junglewise.ai/threats/cve-2026-14457-openssl-null-pointer-dereference-in-rfc7250-raw-public-key"},{"cve":"CVE-2026-9076","cvss":3.7,"slug":"cve-2026-9076-openssl-heap-out-of-bounds-read-in-cms-password-based-decryption","title":"OpenSSL heap out-of-bounds read in CMS password-based decryption","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:50.997+00:00","url":"https://junglewise.ai/threats/cve-2026-9076-openssl-heap-out-of-bounds-read-in-cms-password-based-decryption"},{"cve":"CVE-2026-7383","cvss":8.1,"slug":"cve-2026-7383-openssl-heap-buffer-overflow-in-asn1-mbstring-ncopy","title":"OpenSSL heap buffer overflow in ASN1_mbstring_ncopy","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:50.337+00:00","url":"https://junglewise.ai/threats/cve-2026-7383-openssl-heap-buffer-overflow-in-asn1-mbstring-ncopy"},{"cve":"CVE-2026-45447","cvss":8.1,"slug":"cve-2026-45447-openssl-use-after-free-in-pkcs7-verify","title":"OpenSSL use-after-free in PKCS7_verify","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:19.277+00:00","url":"https://junglewise.ai/threats/cve-2026-45447-openssl-use-after-free-in-pkcs7-verify"},{"cve":"CVE-2026-45446","cvss":0,"slug":"cve-2026-45446-openssl-authentication-bypass-in-aes-siv-and-aes-gcm-siv","title":"OpenSSL authentication bypass in AES-SIV and AES-GCM-SIV","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:19.137+00:00","url":"https://junglewise.ai/threats/cve-2026-45446-openssl-authentication-bypass-in-aes-siv-and-aes-gcm-siv"},{"cve":"CVE-2026-45445","cvss":0,"slug":"cve-2026-45445-openssl-aes-ocb-nonce-reuse-and-forgery-via-evp-cipher-one-shot","title":"OpenSSL AES-OCB nonce reuse and forgery via EVP_Cipher one-shot API","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:18.993+00:00","url":"https://junglewise.ai/threats/cve-2026-45445-openssl-aes-ocb-nonce-reuse-and-forgery-via-evp-cipher-one-shot"},{"cve":"CVE-2026-42771","cvss":0,"slug":"cve-2026-42771-openssl-out-of-bounds-read-in-x509-verify-param-set1-email","title":"OpenSSL out-of-bounds read in X509_VERIFY_PARAM_set1_email","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:08.663+00:00","url":"https://junglewise.ai/threats/cve-2026-42771-openssl-out-of-bounds-read-in-x509-verify-param-set1-email"},{"cve":"CVE-2026-42770","cvss":3.7,"slug":"cve-2026-42770-openssl-private-key-recovery-via-dhx-subgroup-membership-bypass","title":"OpenSSL private key recovery via DHX subgroup membership bypass","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:08.523+00:00","url":"https://junglewise.ai/threats/cve-2026-42770-openssl-private-key-recovery-via-dhx-subgroup-membership-bypass"},{"cve":"CVE-2026-42769","cvss":3.1,"slug":"cve-2026-42769-openssl-improper-certificate-validation-in-cmp-root-ca-update","title":"OpenSSL improper certificate validation in CMP root CA update","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:08.377+00:00","url":"https://junglewise.ai/threats/cve-2026-42769-openssl-improper-certificate-validation-in-cmp-root-ca-update"},{"cve":"CVE-2026-42768","cvss":3.7,"slug":"cve-2026-42768-openssl-bleichenbacher-side-channel-in-cms-and-pkcs7-decryption","title":"OpenSSL Bleichenbacher side-channel in CMS and PKCS7 decryption","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:08.223+00:00","url":"https://junglewise.ai/threats/cve-2026-42768-openssl-bleichenbacher-side-channel-in-cms-and-pkcs7-decryption"},{"cve":"CVE-2026-42767","cvss":0,"slug":"cve-2026-42767-openssl-null-pointer-dereference-in-cmp-client","title":"OpenSSL NULL pointer dereference in CMP client","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:08.093+00:00","url":"https://junglewise.ai/threats/cve-2026-42767-openssl-null-pointer-dereference-in-cmp-client"},{"cve":"CVE-2026-42766","cvss":0,"slug":"cve-2026-42766-openssl-null-pointer-dereference-in-cms-decryption","title":"OpenSSL NULL pointer dereference in CMS decryption","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:07.97+00:00","url":"https://junglewise.ai/threats/cve-2026-42766-openssl-null-pointer-dereference-in-cms-decryption"},{"cve":"CVE-2026-42765","cvss":3.7,"slug":"cve-2026-42765-openssl-null-pointer-dereference-in-certificate-verification","title":"OpenSSL NULL pointer dereference in certificate verification","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:07.843+00:00","url":"https://junglewise.ai/threats/cve-2026-42765-openssl-null-pointer-dereference-in-certificate-verification"},{"cve":"CVE-2026-42764","cvss":5.3,"slug":"cve-2026-42764-openssl-null-pointer-dereference-in-quic-server-initial-packet","title":"OpenSSL NULL pointer dereference in QUIC server initial packet handling","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:07.693+00:00","url":"https://junglewise.ai/threats/cve-2026-42764-openssl-null-pointer-dereference-in-quic-server-initial-packet"},{"cve":"CVE-2026-35188","slug":"cve-2026-35188-openssl-double-free-in-tls-ocsp-stapling-response-handling","title":"OpenSSL double-free in TLS OCSP stapling response handling","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:05.437+00:00","url":"https://junglewise.ai/threats/cve-2026-35188-openssl-double-free-in-tls-ocsp-stapling-response-handling"},{"cve":"CVE-2026-34183","cvss":5.3,"slug":"cve-2026-34183-openssl-memory-exhaustion-in-quic-path-challenge-handler","title":"OpenSSL memory exhaustion in QUIC PATH_CHALLENGE handler","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:05+00:00","url":"https://junglewise.ai/threats/cve-2026-34183-openssl-memory-exhaustion-in-quic-path-challenge-handler"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":2,"exploited":0,"vulnerabilities":9},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"OpenSSL","slug":"openssl","vendor":{"name":"OpenSSL","slug":"openssl","url":"https://junglewise.ai/threats/vendors/openssl"},"aliases":[],"category":"library","homepage":"https://www.openssl.org/","repo_url":"https://github.com/openssl/openssl","description":"A robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.","url":"https://junglewise.ai/threats/technologies/openssl"},"most_severe":[{"cve":"CVE-2014-0160","cvss":7.5,"slug":"cve-2014-0160-openssl-information-disclosure-vulnerability","title":"OpenSSL Information Disclosure Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-04T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2014-0160-openssl-information-disclosure-vulnerability"},{"cve":"CVE-2026-63073","cvss":9.8,"epss":0.0116,"slug":"cve-2026-63073-openssl-cmp-response-validation-format-string","title":"OpenSSL CMP response validation format string","severity":"critical","exploited":false,"published_at":"2026-08-25T13:19:26.147+00:00","url":"https://junglewise.ai/threats/cve-2026-63073-openssl-cmp-response-validation-format-string"},{"cve":"CVE-2026-31789","cvss":9.8,"epss":0.0024,"slug":"cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion","title":"OpenSSL heap buffer overflow in buf2hex conversion","severity":"critical","exploited":false,"published_at":"2026-04-07T22:16:21.617+00:00","url":"https://junglewise.ai/threats/cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion"},{"cve":"CVE-2026-75803","cvss":9.1,"epss":0.0022,"slug":"cve-2026-75803-openssl-chacha20-poly1305-and-aes-ocb-authentication-tag-bypass","title":"OpenSSL ChaCha20-Poly1305 and AES-OCB authentication tag bypass","severity":"critical","exploited":false,"published_at":"2026-08-25T13:19:29.57+00:00","url":"https://junglewise.ai/threats/cve-2026-75803-openssl-chacha20-poly1305-and-aes-ocb-authentication-tag-bypass"},{"cve":"CVE-2024-5535","cvss":9.1,"slug":"cve-2024-5535-openssl-buffer-overread-in-ssl-select-next-proto","title":"OpenSSL buffer overread in SSL_select_next_proto","severity":"critical","exploited":false,"published_at":"2024-06-27T11:15:24.447+00:00","url":"https://junglewise.ai/threats/cve-2024-5535-openssl-buffer-overread-in-ssl-select-next-proto"},{"cve":"CVE-2025-15467","cvss":8.8,"epss":0.0289,"slug":"cve-2025-15467-openssl-stack-buffer-overflow-in-cms-aead-parameter-parsing","title":"OpenSSL stack buffer overflow in CMS AEAD parameter parsing","severity":"high","exploited":false,"published_at":"2026-01-27T16:16:14.257+00:00","url":"https://junglewise.ai/threats/cve-2025-15467-openssl-stack-buffer-overflow-in-cms-aead-parameter-parsing"},{"cve":"CVE-2026-28387","cvss":8.1,"epss":0.008,"slug":"cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication","title":"OpenSSL use-after-free in DANE TLSA-based authentication","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.7+00:00","url":"https://junglewise.ai/threats/cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication"},{"cve":"CVE-2026-7383","cvss":8.1,"slug":"cve-2026-7383-openssl-heap-buffer-overflow-in-asn1-mbstring-ncopy","title":"OpenSSL heap buffer overflow in ASN1_mbstring_ncopy","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:50.337+00:00","url":"https://junglewise.ai/threats/cve-2026-7383-openssl-heap-buffer-overflow-in-asn1-mbstring-ncopy"},{"cve":"CVE-2026-63076","cvss":7.5,"epss":0.0182,"slug":"cve-2026-63076-openssl-cmp-password-protection-verification-null-pointer","title":"OpenSSL CMP password protection verification null pointer dereference","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:26.543+00:00","url":"https://junglewise.ai/threats/cve-2026-63076-openssl-cmp-password-protection-verification-null-pointer"},{"cve":"CVE-2026-18798","cvss":7.5,"epss":0.0154,"slug":"cve-2026-18798-openssl-quic-double-free-in-qrx-object","title":"OpenSSL QUIC double free in QRX object","severity":"high","exploited":false,"published_at":"2026-08-25T13:17:49.813+00:00","url":"https://junglewise.ai/threats/cve-2026-18798-openssl-quic-double-free-in-qrx-object"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}