{"schema_version":1,"title":"OpenSSL vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in OpenSSL: 0 in the last 7 days and 10 in the last 90 days, 5 of them critical and 1 exploited in the wild. The most recent, CVE-2026-90439, was published on 15 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/openssl","json_url":"https://junglewise.ai/threats/vendors/openssl.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/openssl","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":17,"all_time":32,"critical":5,"exploited":1,"last_7_days":0,"last_30_days":1,"last_90_days":10,"last_365_days":27},"latest":[{"cve":"CVE-2026-90439","cvss":6.5,"epss":0.0043,"slug":"cve-2026-90439-nginx-plus-and-open-source-http-3-heap-buffer-overflow-in-tls","title":"NGINX Plus and Open Source HTTP/3 heap buffer overflow in TLS handshake","severity":"medium","exploited":false,"published_at":"2026-09-15T15:17:27.023+00:00","url":"https://junglewise.ai/threats/cve-2026-90439-nginx-plus-and-open-source-http-3-heap-buffer-overflow-in-tls"},{"cve":"CVE-2026-75803","cvss":9.1,"epss":0.0022,"slug":"cve-2026-75803-openssl-chacha20-poly1305-and-aes-ocb-authentication-tag-bypass","title":"OpenSSL ChaCha20-Poly1305 and AES-OCB authentication tag bypass","severity":"critical","exploited":false,"published_at":"2026-08-25T13:19:29.57+00:00","url":"https://junglewise.ai/threats/cve-2026-75803-openssl-chacha20-poly1305-and-aes-ocb-authentication-tag-bypass"},{"cve":"CVE-2026-63076","cvss":7.5,"epss":0.0182,"slug":"cve-2026-63076-openssl-cmp-password-protection-verification-null-pointer","title":"OpenSSL CMP password protection verification null pointer dereference","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:26.543+00:00","url":"https://junglewise.ai/threats/cve-2026-63076-openssl-cmp-password-protection-verification-null-pointer"},{"cve":"CVE-2026-63075","cvss":7.5,"epss":0.0078,"slug":"cve-2026-63075-openssl-quic-memory-exhaustion-denial-of-service","title":"OpenSSL QUIC memory exhaustion denial of service","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:26.413+00:00","url":"https://junglewise.ai/threats/cve-2026-63075-openssl-quic-memory-exhaustion-denial-of-service"},{"cve":"CVE-2026-63074","cvss":5.9,"epss":0.0056,"slug":"cve-2026-63074-openssl-cmp-unbounded-certificate-cache-growth","title":"OpenSSL CMP unbounded certificate cache growth","severity":"medium","exploited":false,"published_at":"2026-08-25T13:19:26.283+00:00","url":"https://junglewise.ai/threats/cve-2026-63074-openssl-cmp-unbounded-certificate-cache-growth"},{"cve":"CVE-2026-63073","cvss":9.8,"epss":0.0116,"slug":"cve-2026-63073-openssl-cmp-response-validation-format-string","title":"OpenSSL CMP response validation format string","severity":"critical","exploited":false,"published_at":"2026-08-25T13:19:26.147+00:00","url":"https://junglewise.ai/threats/cve-2026-63073-openssl-cmp-response-validation-format-string"},{"cve":"CVE-2026-63072","cvss":7.5,"epss":0.0101,"slug":"cve-2026-63072-openssl-heap-overflow-in-cms-key-unwrap","title":"OpenSSL heap overflow in CMS key unwrap","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:26.01+00:00","url":"https://junglewise.ai/threats/cve-2026-63072-openssl-heap-overflow-in-cms-key-unwrap"},{"cve":"CVE-2026-54874","cvss":7.5,"epss":0.0131,"slug":"cve-2026-54874-openssl-dtls-memory-exhaustion-in-epoch-buffering","title":"OpenSSL DTLS memory exhaustion in epoch buffering","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:24.033+00:00","url":"https://junglewise.ai/threats/cve-2026-54874-openssl-dtls-memory-exhaustion-in-epoch-buffering"},{"cve":"CVE-2026-18798","cvss":7.5,"epss":0.0154,"slug":"cve-2026-18798-openssl-quic-double-free-in-qrx-object","title":"OpenSSL QUIC double free in QRX object","severity":"high","exploited":false,"published_at":"2026-08-25T13:17:49.813+00:00","url":"https://junglewise.ai/threats/cve-2026-18798-openssl-quic-double-free-in-qrx-object"},{"cve":"CVE-2026-14457","cvss":7.5,"epss":0.0102,"slug":"cve-2026-14457-openssl-null-pointer-dereference-in-rfc7250-raw-public-key","title":"OpenSSL NULL pointer dereference in RFC7250 Raw Public Key handling","severity":"high","exploited":false,"published_at":"2026-08-25T13:17:49.533+00:00","url":"https://junglewise.ai/threats/cve-2026-14457-openssl-null-pointer-dereference-in-rfc7250-raw-public-key"},{"cve":"CVE-2026-45446","cvss":0,"slug":"cve-2026-45446-openssl-authentication-bypass-in-aes-siv-and-aes-gcm-siv","title":"OpenSSL authentication bypass in AES-SIV and AES-GCM-SIV","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:19.137+00:00","url":"https://junglewise.ai/threats/cve-2026-45446-openssl-authentication-bypass-in-aes-siv-and-aes-gcm-siv"},{"cve":"CVE-2026-42771","cvss":0,"slug":"cve-2026-42771-openssl-out-of-bounds-read-in-x509-verify-param-set1-email","title":"OpenSSL out-of-bounds read in X509_VERIFY_PARAM_set1_email","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:08.663+00:00","url":"https://junglewise.ai/threats/cve-2026-42771-openssl-out-of-bounds-read-in-x509-verify-param-set1-email"},{"cve":"CVE-2026-42770","cvss":3.7,"slug":"cve-2026-42770-openssl-private-key-recovery-via-dhx-subgroup-membership-bypass","title":"OpenSSL private key recovery via DHX subgroup membership bypass","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:08.523+00:00","url":"https://junglewise.ai/threats/cve-2026-42770-openssl-private-key-recovery-via-dhx-subgroup-membership-bypass"},{"cve":"CVE-2026-42767","cvss":0,"slug":"cve-2026-42767-openssl-null-pointer-dereference-in-cmp-client","title":"OpenSSL NULL pointer dereference in CMP client","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:08.093+00:00","url":"https://junglewise.ai/threats/cve-2026-42767-openssl-null-pointer-dereference-in-cmp-client"},{"cve":"CVE-2026-42766","cvss":0,"slug":"cve-2026-42766-openssl-null-pointer-dereference-in-cms-decryption","title":"OpenSSL NULL pointer dereference in CMS decryption","severity":"info","exploited":false,"published_at":"2026-06-09T17:17:07.97+00:00","url":"https://junglewise.ai/threats/cve-2026-42766-openssl-null-pointer-dereference-in-cms-decryption"},{"cve":"CVE-2026-31790","cvss":7.5,"epss":0.012,"slug":"cve-2026-31790-openssl-uninitialized-memory-disclosure-in-rsasve-key","title":"OpenSSL uninitialized memory disclosure in RSASVE key encapsulation","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.77+00:00","url":"https://junglewise.ai/threats/cve-2026-31790-openssl-uninitialized-memory-disclosure-in-rsasve-key"},{"cve":"CVE-2026-31789","cvss":9.8,"epss":0.0024,"slug":"cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion","title":"OpenSSL heap buffer overflow in buf2hex conversion","severity":"critical","exploited":false,"published_at":"2026-04-07T22:16:21.617+00:00","url":"https://junglewise.ai/threats/cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion"},{"cve":"CVE-2026-28390","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28390-openssl-null-pointer-dereference-in-cms-envelopeddata-processing","title":"OpenSSL NULL pointer dereference in CMS EnvelopedData processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.19+00:00","url":"https://junglewise.ai/threats/cve-2026-28390-openssl-null-pointer-dereference-in-cms-envelopeddata-processing"},{"cve":"CVE-2026-28389","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28389-openssl-null-pointer-dereference-in-cms-envelopeddata-processing","title":"OpenSSL NULL pointer dereference in CMS EnvelopedData processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.03+00:00","url":"https://junglewise.ai/threats/cve-2026-28389-openssl-null-pointer-dereference-in-cms-envelopeddata-processing"},{"cve":"CVE-2026-28388","cvss":7.5,"epss":0.0106,"slug":"cve-2026-28388-openssl-null-pointer-dereference-in-delta-crl-processing","title":"OpenSSL NULL pointer dereference in delta CRL processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.863+00:00","url":"https://junglewise.ai/threats/cve-2026-28388-openssl-null-pointer-dereference-in-delta-crl-processing"},{"cve":"CVE-2026-28387","cvss":8.1,"epss":0.008,"slug":"cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication","title":"OpenSSL use-after-free in DANE TLSA-based authentication","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.7+00:00","url":"https://junglewise.ai/threats/cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication"},{"cve":"CVE-2026-28386","cvss":7.5,"epss":0.0031,"slug":"cve-2026-28386-openssl-aes-cfb128-out-of-bounds-read-on-avx-512-systems","title":"OpenSSL AES-CFB128 out-of-bounds read on AVX-512 systems","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.513+00:00","url":"https://junglewise.ai/threats/cve-2026-28386-openssl-aes-cfb128-out-of-bounds-read-on-avx-512-systems"},{"cve":"CVE-2026-22796","cvss":5.3,"slug":"cve-2026-22796-openssl-type-confusion-in-pkcs-7-signature-verification","title":"OpenSSL type confusion in PKCS#7 signature verification","severity":"medium","exploited":false,"published_at":"2026-01-27T16:16:35.543+00:00","url":"https://junglewise.ai/threats/cve-2026-22796-openssl-type-confusion-in-pkcs-7-signature-verification"},{"cve":"CVE-2025-69421","cvss":7.5,"slug":"cve-2025-69421-openssl-null-pointer-dereference-in-pkcs12-item-decrypt-d2i-ex","title":"OpenSSL NULL pointer dereference in PKCS12_item_decrypt_d2i_ex","severity":"high","exploited":false,"published_at":"2026-01-27T16:16:34.437+00:00","url":"https://junglewise.ai/threats/cve-2025-69421-openssl-null-pointer-dereference-in-pkcs12-item-decrypt-d2i-ex"},{"cve":"CVE-2025-69420","cvss":7.5,"slug":"cve-2025-69420-openssl-type-confusion-in-timestamp-response-verification","title":"OpenSSL type confusion in TimeStamp Response verification","severity":"high","exploited":false,"published_at":"2026-01-27T16:16:34.317+00:00","url":"https://junglewise.ai/threats/cve-2025-69420-openssl-type-confusion-in-timestamp-response-verification"}],"vendor":{"hub":true,"name":"OpenSSL","slug":"openssl","homepage":"https://www.openssl.org/","description":"OpenSSL is an open-source software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end.","url":"https://junglewise.ai/threats/vendors/openssl"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":2,"exploited":0,"vulnerabilities":9},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2014-0160","cvss":7.5,"slug":"cve-2014-0160-openssl-information-disclosure-vulnerability","title":"OpenSSL Information Disclosure Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-04T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2014-0160-openssl-information-disclosure-vulnerability"},{"cve":"CVE-2026-63073","cvss":9.8,"epss":0.0116,"slug":"cve-2026-63073-openssl-cmp-response-validation-format-string","title":"OpenSSL CMP response validation format string","severity":"critical","exploited":false,"published_at":"2026-08-25T13:19:26.147+00:00","url":"https://junglewise.ai/threats/cve-2026-63073-openssl-cmp-response-validation-format-string"},{"cve":"CVE-2026-31789","cvss":9.8,"epss":0.0024,"slug":"cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion","title":"OpenSSL heap buffer overflow in buf2hex conversion","severity":"critical","exploited":false,"published_at":"2026-04-07T22:16:21.617+00:00","url":"https://junglewise.ai/threats/cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion"},{"cve":"CVE-2026-75803","cvss":9.1,"epss":0.0022,"slug":"cve-2026-75803-openssl-chacha20-poly1305-and-aes-ocb-authentication-tag-bypass","title":"OpenSSL ChaCha20-Poly1305 and AES-OCB authentication tag bypass","severity":"critical","exploited":false,"published_at":"2026-08-25T13:19:29.57+00:00","url":"https://junglewise.ai/threats/cve-2026-75803-openssl-chacha20-poly1305-and-aes-ocb-authentication-tag-bypass"},{"cve":"CVE-2024-5535","cvss":9.1,"slug":"cve-2024-5535-openssl-buffer-overread-in-ssl-select-next-proto","title":"OpenSSL buffer overread in SSL_select_next_proto","severity":"critical","exploited":false,"published_at":"2024-06-27T11:15:24.447+00:00","url":"https://junglewise.ai/threats/cve-2024-5535-openssl-buffer-overread-in-ssl-select-next-proto"},{"cve":"CVE-2026-28387","cvss":8.1,"epss":0.008,"slug":"cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication","title":"OpenSSL use-after-free in DANE TLSA-based authentication","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.7+00:00","url":"https://junglewise.ai/threats/cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication"},{"cve":"CVE-2026-63076","cvss":7.5,"epss":0.0182,"slug":"cve-2026-63076-openssl-cmp-password-protection-verification-null-pointer","title":"OpenSSL CMP password protection verification null pointer dereference","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:26.543+00:00","url":"https://junglewise.ai/threats/cve-2026-63076-openssl-cmp-password-protection-verification-null-pointer"},{"cve":"CVE-2026-18798","cvss":7.5,"epss":0.0154,"slug":"cve-2026-18798-openssl-quic-double-free-in-qrx-object","title":"OpenSSL QUIC double free in QRX object","severity":"high","exploited":false,"published_at":"2026-08-25T13:17:49.813+00:00","url":"https://junglewise.ai/threats/cve-2026-18798-openssl-quic-double-free-in-qrx-object"},{"cve":"CVE-2026-54874","cvss":7.5,"epss":0.0131,"slug":"cve-2026-54874-openssl-dtls-memory-exhaustion-in-epoch-buffering","title":"OpenSSL DTLS memory exhaustion in epoch buffering","severity":"high","exploited":false,"published_at":"2026-08-25T13:19:24.033+00:00","url":"https://junglewise.ai/threats/cve-2026-54874-openssl-dtls-memory-exhaustion-in-epoch-buffering"},{"cve":"CVE-2026-31790","cvss":7.5,"epss":0.012,"slug":"cve-2026-31790-openssl-uninitialized-memory-disclosure-in-rsasve-key","title":"OpenSSL uninitialized memory disclosure in RSASVE key encapsulation","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.77+00:00","url":"https://junglewise.ai/threats/cve-2026-31790-openssl-uninitialized-memory-disclosure-in-rsasve-key"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"OpenSSL","slug":"openssl","vulnerabilities":59,"url":"https://junglewise.ai/threats/technologies/openssl"}]}