OpenSSL Security Update Advisory (CVE-2026-54876)
Overview
A security update addressing the CVE-2026-54876 vulnerability in OpenSSL has been released.
Affected Products
- OpenSSL versions 3.6.0 Through 3.6.4.
- OpenSSL versions 4.0.0 Through 4.0.2.
Vulnerability Details
- CVE-2026-54876 is a denial-of-service (DoS) vulnerability caused by a memory leak in OpenSSL’s OCSP response validation.
Mitigation Steps
- A Vulnerability Patch for this vulnerability is available in the latest update.
- Update to OpenSSL version 3.6.4 Or later, or to a version that includes commit 155b5fe.
- Update to OpenSSL version 4.0.2 Or later, or to a version that includes commit d8c5104.