O

OpenSSL Releases

O
OpenSSL Releases Security v4.1.0-alpha1

OpenSSL 4.1.0-alpha1

OpenSSL 4.1.0 is a feature release adding significant new functionality to OpenSSL. This release incorporates the following potentially significant or incompatible changes: Added VC-WIN32-MSVC2013 and VC-WIN64A-MSVC2013 build targets to provide internal functions for bridging the gaps in C99 standard support that are present in MSVC 2013. Added optimized ML-DSA and ML-KEM NTT operations on ppc64le…

O
OpenSSL Releases Security v3.0.22

OpenSSL 3.0.22

OpenSSL 3.0.22 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072) Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076) Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-…

O
OpenSSL Releases Security v3.4.7

OpenSSL 3.4.7

OpenSSL 3.4.7 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072) Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076) Fixed RPK server signature algorithm selection being able to dereference a m…

O
OpenSSL Releases Security v3.5.8

OpenSSL 3.5.8

OpenSSL 3.5.8 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798) Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072) Fixed invalid pointer dereference in CMP server via crafted protect…

O
OpenSSL Releases Security v3.6.4

OpenSSL 3.6.4

OpenSSL 3.6.4 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798) Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072) Fixed invalid pointer dereference in CMP server via crafted protect…

O
OpenSSL Releases Security v4.0.2

OpenSSL 4.0.2

OpenSSL 4.0.2 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798) Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072) Fixed invalid pointer dereference in CMP server via crafted protect…

O
OpenSSL Releases Security v3.0.21

OpenSSL 3.0.21

OpenSSL 3.0.21 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed AES-OCB IV ignored on EVP_Cipher() path. (CVE-2026-45445) Fixed possible heap buffer o…

O
OpenSSL Releases Security v3.4.6

OpenSSL 3.4.6

OpenSSL 3.4.6 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183) Fixed AES-…

O
OpenSSL Releases Security v3.5.7

OpenSSL 3.5.7

OpenSSL 3.5.7 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183) Fixed NULL…

O
OpenSSL Releases Security v3.6.3

OpenSSL 3.6.3

OpenSSL 3.6.3 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183) Fixed doub…

O
OpenSSL Releases Security v4.0.1

OpenSSL 4.0.1

OpenSSL 4.0.1 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183) Fixed doub…

O
OpenSSL Releases Security v4.0.0

OpenSSL 4.0.0

OpenSSL 4.0.0 is a feature release adding significant new functionality to OpenSSL. This release incorporates the following potentially significant or incompatible changes: Removed extra leading '00:' when printing key data such as an RSA modulus in hexadecimal format where the first (most significant) byte is >= 0x80. Standardized the width of hexadecimal dumps to 24 bytes for signatures (to stay…

O
OpenSSL Releases Security v3.3.7

OpenSSL 3.3.7

OpenSSL 3.3.7 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. (CVE-2026-31790) Fixed potential use-after-free in DANE client code. (CVE-2026-28387) Fixed NULL pointer dereference when processing a delta CRL. (CVE-2026-28388) Fixed…

O
OpenSSL Releases Security v3.4.5

OpenSSL 3.4.5

OpenSSL 3.4.5 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. (CVE-2026-31790) Fixed potential use-after-free in DANE client code. (CVE-2026-28387) Fixed NULL pointer dereference when processing a delta CRL. (CVE-2026-28388) Fixed…

O
OpenSSL Releases Security v3.5.6

OpenSSL 3.5.6

OpenSSL 3.5.6 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. (CVE-2026-31790) Fixed loss of key agreement group tuple structure when the DEFAULT keyword is used in the server-side configuration of the key-agreement group list. (CV…

O
OpenSSL Releases Security v3.6.2

OpenSSL 3.6.2

OpenSSL 3.6.2 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. (CVE-2026-31790) Fixed loss of key agreement group tuple structure when the DEFAULT keyword is used in the server-side configuration of the key-agreement group list. (CV…