Known vulnerabilities in OpenSSL

Software: OpenSSL
Software CPE: cpe:2.3:a:openssl_software_foundation:openssl:*:*:*:*:*:*:*:*
Total vulnerabilities: 243
Public exploits: 26
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenSSL OpenSSL is affected by 243 known vulnerabilities: 2 critical, 15 high, 146 medium, 80 low Critical High Medium Low

Vulnerabilities (243)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU152952 - Use After Free
CVE-2026-84783
CWE-416 Medium
No
No
4.0.3 30.09.2026 SB2026093079
#VU152953 - Allocation of Resources Without Limits or Throttling
CVE-2026-35189
CWE-770 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001103
and 5 more
#VU152954 - Expected Behavior Violation
CVE-2026-35191
CWE-440 Low
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001112
and 1 more
#VU152955 - Inefficient Algorithmic Complexity
CVE-2026-42772
CWE-407 Low
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB2026100195
#VU152956 - Information Exposure Through Timing Discrepancy
CVE-2026-54872
CWE-208 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001103
and 5 more
#VU152957 - Allocation of Resources Without Limits or Throttling
CVE-2026-54873
CWE-770 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB2026100195
#VU152958 - Information Exposure Through Timing Discrepancy
CVE-2026-54875
CWE-208 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001112
and 1 more
#VU152959 - Out-of-bounds write
CVE-2026-72897
CWE-787 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001112
and 1 more
#VU152960 - Allocation of Resources Without Limits or Throttling
CVE-2026-75804
CWE-770 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001112
and 1 more
#VU152961 - NULL Pointer Dereference
CVE-2026-75805
CWE-476 Low
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001112
and 4 more
#VU152962 - Improper Validation of Specified Quantity in Input
CVE-2026-75806
CWE-1284 Low
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001112
and 4 more
#VU152963 - Information Exposure Through Timing Discrepancy
CVE-2026-77696
CWE-208 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001103
and 5 more
#VU152964 - Allocation of Resources Without Limits or Throttling
CVE-2026-84784
CWE-770 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093091
SB20261001112
and 1 more
#VU152944 - Out-of-bounds read
CVE-2026-84782
CWE-125 Medium
No
No
1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 30.09.2026 SB2026093079
SB2026093080
SB2026093091
and 7 more
#VU145416 - Double Free
CVE-2026-18798
CWE-415 Medium
No
No
3.5.8, 3.6.4, 4.0.2 26.08.2026 SB2026082627
SB2026082629
SB2026082636
and 4 more
#VU145417 - Out-of-bounds write
CVE-2026-63072
CWE-787 Medium
No
No
1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2 26.08.2026 SB2026082627
SB2026082629
SB2026082636
and 32 more
#VU145418 - NULL Pointer Dereference
CVE-2026-63076
CWE-476 Medium
No
No
3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2 26.08.2026 SB2026082627
SB2026082629
SB2026082636
and 16 more
#VU145419 - NULL Pointer Dereference
CVE-2026-14457
CWE-476 Medium
No
No
3.4.7, 3.5.8, 3.6.4, 4.0.2 26.08.2026 SB2026082627
SB2026082629
SB2026082636
and 6 more
#VU145420 - Asymmetric Resource Consumption (Amplification)
CVE-2026-54874
CWE-405 Medium
No
No
1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2 26.08.2026 SB2026082627
SB2026082629
SB2026082636
and 23 more
#VU145421 - Use of Externally-Controlled Format String
CVE-2026-63073
CWE-134 Medium
No
No
3.4.7, 3.5.8, 3.6.4, 4.0.2 26.08.2026 SB2026082627
SB2026082629
SB2026082636
and 4 more


Showing elements 1 - 20 out of 243