OpenSSL Security Update Advisory (CVE-2026-54876)

OpenSSL Security Update Advisory (CVE-2026-54876)

Overview


A security update addressing the CVE-2026-54876 vulnerability in OpenSSL has been released.

Affected Products


  • OpenSSL versions 3.6.0 Through 3.6.4.
  • OpenSSL versions 4.0.0 Through 4.0.2.

Vulnerability Details


  • CVE-2026-54876 is a denial-of-service (DoS) vulnerability caused by a memory leak in OpenSSL’s OCSP response validation.

Mitigation Steps


  • A Vulnerability Patch for this vulnerability is available in the latest update.
  • Update to OpenSSL version 3.6.4 Or later, or to a version that includes commit 155b5fe.
  • Update to OpenSSL version 4.0.2 Or later, or to a version that includes commit d8c5104.