Vulnerabilities in OpenSSL

128 results
Vexday analysis

Com 117 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o OpenSSL apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que não elimina a necessidade de atenção — especialmente considerando que 25 vulnerabilidades surgiram nos últimos 90 dias e 5 possuem PoC pública disponível. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), padrão recorrente em bibliotecas criptográficas de baixo nível que pode resultar em condições de negação de serviço. A CVE mais crítica em destaque, CVE-2022-2068, registra EPSS de 0,9576 — valor altamente elevado que indica forte probabilidade estatística de exploração —, sendo recomendada sua priorização imediata em qualquer inventário que utilize versões afetadas da biblioteca.

CVE-2023-2975MEDIUMAES-SIV implementation ignores empty associated data entriesEPSS 0.6%CVE-2024-13176MEDIUMTiming side-channel in ECDSA signature computationEPSS 0.6%CVE-2026-34182CRITICALCMS AuthEnvelopedData Processing May Accept Forged MessagesEPSS 0.6%CVE-2026-42768LOWMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()EPSS 0.6%CVE-2025-69419HIGHOut of bounds write in PKCS12_get_friendlyname() UTF-8 conversionEPSS 0.6%CVE-2026-42767MEDIUMNULL Pointer Dereference in CRMF EncryptedValue DecryptionEPSS 0.6%CVE-2026-54874HIGHExcessive Memory Use Buffering DTLS Records for a Future EpochEPSS 0.5%CVE-2026-22796MEDIUMASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() functionEPSS 0.5%CVE-2026-42765HIGHNULL Dereference in Certificate Verification with OCSP CheckingEPSS 0.5%CVE-2026-42770LOWFFC-DH Peer Validation Uses Attacker-Supplied qEPSS 0.5%CVE-2026-63074MEDIUMCMP Indefinite Cache Growth of ExtraCertsEPSS 0.5%CVE-2026-63075HIGHQUIC ACK-only Packet Retention Can Cause Memory ExhaustionEPSS 0.5%CVE-2026-45446MEDIUMIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modesEPSS 0.4%CVE-2026-2673MEDIUMOpenSSL TLS 1.3 server may choose unexpected key agreement groupEPSS 0.4%CVE-2025-66199MEDIUMTLS 1.3 CompressedCertificate excessive memory allocationEPSS 0.4%CVE-2026-42769MEDIUMTrust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdateEPSS 0.4%CVE-2025-4575MEDIUMThe x509 application adds trusted use instead of rejected useEPSS 0.4%CVE-2026-28386CRITICALOut-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 SupportEPSS 0.3%CVE-2026-35188MEDIUMDouble-free When Checking OCSP Stapled ResponseEPSS 0.3%CVE-2026-54876HIGHClient-Side Memory Leak in OCSP Response CheckingEPSS 0.3%