OpenSSL 4.1.0-alpha1

2026-09-10T08:51:57Z5d872ee27c969af3d903d249b574d67252fdf35e055777504eb85488a9d3aa28
CVE-2026-14456CVE-2026-14457CVE-2026-18798CVE-2026-34180CVE-2026-34182CVE-2026-34183CVE-2026-35188CVE-2026-42764CVE-2026-45445CVE-2026-45447CVE-2026-54874CVE-2026-54876CVE-2026-63072CVE-2026-63073CVE-2026-63074CVE-2026-63075CVE-2026-63076CVE-2026-7383CVE-2026-75803CVE-2026-9076AEADASN.1CMPCMSDTLSNULL-pointer-dereferenceOCSPOpenSSLPKCS7QUICcryptographic-librarydenial-of-servicedouble-freeheap-buffer-overflowmemory-corruptionrelease-advisorysecurity-updatesoftware-updatesuse-after-free

What happened

OpenSSL release feed covering OpenSSL 4.1.0-alpha1 feature development and multiple 2026 security patch releases across supported branches. The patches address memory-safety flaws, denial-of-service conditions, cryptographic validation issues, forged-message acceptance, and protocol implementation bugs in QUIC, DTLS, CMS, CMP, OCSP, PKCS#7, ASN.1, and AEAD processing. The most severe issue explicitly identified is High, including a heap use-after-free in PKCS7_verify() and related vulnerabilities.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
openssl_releases
Record identifier
5d872ee27c969af3d903d249b574d67252fdf35e055777504eb85488a9d3aa28
Enrichment time
2026-09-10T08:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OpenSSL 4.1.0-alpha1 · Baitaphish