CVE Explorer
CVE-2026-45445
Issue summary: When an application drives an AES-OCB context through the
public EVP_Cipher() one-shot interface, the application-supplied
initialisation vector (IV) is silently discarded.
Impact summary: Every message encrypted under the same key uses the
same effective nonce regardless of the IV supplied by the caller,
resulting in (key, nonce) reuse and loss of confidentiality. If the
same code path is used to compute the authentication tag, the tag
depends only on the (key, IV) pair and not
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"OpenSSL","vendor":"OpenSSL","versions":[{"lessThan":"4.0.1","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"3.6.3","status":"affected","version":"3.6.0","versionType":"semver"},{"lessThan":"3.5.7","status":"affected","version":"3.5.0","versionType":"semver"},{"lessThan":"3.4.6","status":"affected","version":"3.4.0","versionType":"semver"},{"lessThan":"3.0.21","status":"affected","version":"3.0.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-325","description":"CWE-325 Missing Cryptographic Step","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/cna/problemTypes/0/descriptions/0
Source references
6 source assertions{"name":"3.0.21 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/cna/references/5
{"name":"3.6.3 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/cna/references/2
{"name":"3.4.6 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/cna/references/4
{"name":"4.0.1 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/cna/references/1
{"name":"3.5.7 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/cna/references/3
{"name":"OpenSSL Advisory","tags":["vendor-advisory"],"url":"https://openssl-library.org/news/secadv/20260609.txt"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:15fea3c0dbc4097d44d34dff4ae1e0db6eadbdf3520efa28682fc9006a211d84 · sha256:86b1ca452c344462… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.