vendor
openssl
Severity
Its products
Being told
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() CVE-2026-75803 | Severity critical |
| openssl: invalid pointer dereference in CMP server via crafted protectionAlg CVE-2026-63076 | Severity high |
| openssl: QUIC ACK-only packet retention can cause memory exhaustion CVE-2026-63075 | Severity high |
| openssl: CMP indefinite cache growth of ExtraCerts CVE-2026-63074 | Severity medium |
| openssl: untrusted sender DN used as format string in CMP response validation CVE-2026-63073 | Severity critical |
| openssl: heap buffer overflow in CMS key unwrapping CVE-2026-63072 | Severity high |
| openssl: excessive memory use buffering DTLS records for a future epoch CVE-2026-54874 | Severity high |
| openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() CVE-2026-45447 | Severity high |
| openssl: QUIC server may trigger double free when processing INITIAL packet CVE-2026-18798 | Severity high |
| openssl: RPK server signature algorithm selection can dereference a missing certificate CVE-2026-14457 | Severity high |