Openssl
38 known vulnerabilities
Top Products
Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an
Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy()
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signatur
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD
Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the app
Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, s
Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly check
Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Mana
Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacke
Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer derefere
Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decr
Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the who
Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenS
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ
Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe
Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an
Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflo
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer de
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer derefe
Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference mi
Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with u
Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigg
Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key ex
Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_T
Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.
Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i
Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE unio
Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs
Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf
Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp
Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing al
Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigg
Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow
Frequently Asked Questions
How many CVEs affect Openssl?
Openssl has 38 CVE records in our database, including 2 critical and 19 high severity vulnerabilities.
What are the most severe Openssl vulnerabilities?
Openssl has 2 critical severity (CVSS 9.0+) and 19 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Openssl vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Openssl products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Openssl Vulnerabilities
CyberStrike scans your infrastructure for Openssl vulnerabilities and provides real-time remediation guidance.
Get Started