O

OpenSSL Releases

O
OpenSSL Releases Security v3.0.21

OpenSSL 3.0.21

OpenSSL 3.0.21 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed AES-OCB IV ignored on EVP_Cipher() path. (CVE-2026-45445) Fixed possible heap buffer o…

O
OpenSSL Releases Security v3.4.6

OpenSSL 3.4.6

OpenSSL 3.4.6 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183) Fixed AES-…

O
OpenSSL Releases Security v3.5.7

OpenSSL 3.5.7

OpenSSL 3.5.7 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183) Fixed NULL…

O
OpenSSL Releases Security v3.6.3

OpenSSL 3.6.3

OpenSSL 3.6.3 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183) Fixed doub…

O
OpenSSL Releases Security v4.0.1

OpenSSL 4.0.1

OpenSSL 4.0.1 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183) Fixed doub…

O
OpenSSL Releases Security v4.0.0

OpenSSL 4.0.0

OpenSSL 4.0.0 is a feature release adding significant new functionality to OpenSSL. This release incorporates the following potentially significant or incompatible changes: Removed extra leading '00:' when printing key data such as an RSA modulus in hexadecimal format where the first (most significant) byte is >= 0x80. Standardized the width of hexadecimal dumps to 24 bytes for signatures (to stay…

O
OpenSSL Releases Security v3.3.7

OpenSSL 3.3.7

OpenSSL 3.3.7 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. (CVE-2026-31790) Fixed potential use-after-free in DANE client code. (CVE-2026-28387) Fixed NULL pointer dereference when processing a delta CRL. (CVE-2026-28388) Fixed…

O
OpenSSL Releases Security v3.4.5

OpenSSL 3.4.5

OpenSSL 3.4.5 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. (CVE-2026-31790) Fixed potential use-after-free in DANE client code. (CVE-2026-28387) Fixed NULL pointer dereference when processing a delta CRL. (CVE-2026-28388) Fixed…

O
OpenSSL Releases Security v3.5.6

OpenSSL 3.5.6

OpenSSL 3.5.6 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. (CVE-2026-31790) Fixed loss of key agreement group tuple structure when the DEFAULT keyword is used in the server-side configuration of the key-agreement group list. (CV…

O
OpenSSL Releases Security v3.6.2

OpenSSL 3.6.2

OpenSSL 3.6.2 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. (CVE-2026-31790) Fixed loss of key agreement group tuple structure when the DEFAULT keyword is used in the server-side configuration of the key-agreement group list. (CV…