OpenSSL 4.0.0-beta1

2026-03-25T08:52:10Z22e6524e6fd968baa533ac615488c56b6f75a4794309e2688084827493c21112
ASN.1CMSCVEFIPSPKCS#12TLScryptodeprecationengine-removalopensslreleasesecurityssl3vulnerability

What happened

OpenSSL published multiple releases: feature previews (4.0.0-alpha1 and 4.0.0-beta1) introducing API/ABI changes (ASN1_STRING made opaque, many X.509 API constness changes, deprecated X509_cmp_* APIs, PKCS5_PBKDF2_HMAC lower-bound checks for FIPS, AKID checks under X509_V_FLAG_X509_STRICT, augmented CRL checks), removal of SSLv2 Client Hello and SSLv3 support, removal of engine support, changes to libcrypto cleanup behavior, and formatting changes for hex dumps. In addition a series of security patch releases (3.6.1, 3.5.5, 3.4.4, 3.3.6, 3.0.19) fix multiple vulnerabilities — most severe rated

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
openssl_releases
Record identifier
22e6524e6fd968baa533ac615488c56b6f75a4794309e2688084827493c21112
Enrichment time
2026-03-25T08:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.