OpenSSL 3.0.21
OpenSSL 3.0.21 is a security patch release. The most severe CVE fixed in this release is High. This release incorporates the following bug fixes and mitigations: Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447) Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182) Fixed AES-OCB IV ignored on EVP_Cipher() path. (CVE-2026-45445) Fixed possible heap buffer o…