OpenSSL 4.0.0-beta1
2026-03-25T08:52:10Z•22e6524e6fd968baa533ac615488c56b6f75a4794309e2688084827493c21112
ASN.1CMSCVEFIPSPKCS#12TLScryptodeprecationengine-removalopensslreleasesecurityssl3vulnerability
What happened
OpenSSL published multiple releases: feature previews (4.0.0-alpha1 and 4.0.0-beta1) introducing API/ABI changes (ASN1_STRING made opaque, many X.509 API constness changes, deprecated X509_cmp_* APIs, PKCS5_PBKDF2_HMAC lower-bound checks for FIPS, AKID checks under X509_V_FLAG_X509_STRICT, augmented CRL checks), removal of SSLv2 Client Hello and SSLv3 support, removal of engine support, changes to libcrypto cleanup behavior, and formatting changes for hex dumps. In addition a series of security patch releases (3.6.1, 3.5.5, 3.4.4, 3.3.6, 3.0.19) fix multiple vulnerabilities — most severe rated
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- openssl_releases
- Record identifier
- 22e6524e6fd968baa533ac615488c56b6f75a4794309e2688084827493c21112
- Enrichment time
- 2026-03-25T08:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.