OpenSSL Product Security Update Advisory

OpenSSL Product Security Update Advisory

Overview


A security update has been released to address a vulnerability in OpenSSL products. users of the affected products should update to the latest version of the Vulnerability Patch.

Affected by


  • CVE-2026-34181, CVE-2026-34183.
    • OpenSSL 4.0 and above, but below 4.0.1.
    • OpenSSL 3.6 or later but not earlier than 3.6.3.
    • OpenSSL 3.5 or later but less than 3.5.7.
    • OpenSSL 3.4 or later but less than 3.4.6.
  • CVE-2026-34182.
    • OpenSSL 4.0 or later but less than 4.0.1.
    • OpenSSL 3.6 or later but less than 3.6.3.
    • OpenSSL 3.5 or later but less than 3.5.7.
    • OpenSSL 3.4 or later but less than 3.4.6.
    • OpenSSL 3.0 or later but less than 3.0.21.

Resolved vulnerabilities


  • Certificate and private key forgery vulnerability in OpenSSL (CVE-2026-34181).
  • Forged message acceptance vulnerability in OpenSSL (CVE-2026-34182).
  • Denial of Service vulnerability in OpenSSL (CVE-2026-34183).

Advisory


vulnerability patches have been made available in the latest update, and you should update to the latest version of the Vulnerability Patch by following the instructions on the reference site.

Patch version


  • CVE-2026-34181, CVE-2026-34183.
    • OpenSSL 4.0.1.
    • OpenSSL 3.6.3.
    • OpenSSL 3.5.7.
    • OpenSSL 3.4.6.
  • CVE-2026-34182.
    • OpenSSL 4.0.1.
    • OpenSSL 3.6.3.
    • OpenSSL 3.5.7.
    • OpenSSL 3.4.6.
    • OpenSSL 3.0.21.