Skip to content

OpenSSL vulnerabilities

3 CVEs tracked

OpenSSL appears in recent reporting in both a direct and indirect critical context. Directly, CVE-2026-14456 describes a vulnerability in the QUIC server where a missing limit on new incoming channels can lead to remote resource exhaustion (DoS). Indirectly, CVE-2026-14663 highlights OpenSSL's version and configuration as a factor in a pgcrypto cleartext storage weakness in PostgreSQL, and CVE-2026-66402 points to TLS certificate identity validation weaknesses in FreeRDP related to custom hostname matching. Defenders should prioritize configuring QUIC server limits, updating OpenSSL versions, and ensuring proper certificate validation mechanisms in dependent software like PostgreSQL and FreeRDP.

Azərbaycanca: OpenSSL son hesabatlarda həm birbaşa, həm də dolayı yolla kritik kontekstdə görünür. Birbaşa olaraq, CVE-2026-14456 identifikatorlu boşluq QUIC serverində yeni kanal limitinin tətbiq edilməməsi səbəbindən uzaqdan resurs tükənməsinə (DoS) şərait yaradır. Dolayı yolla isə CVE-2026-14663 PostgreSQL-in pgcrypto modulunda şifrələmə zəifliyinə, CVE-2026-66402 isə FreeRDP-də TLS sertifikat yoxlaması problemlərinə səbəb kimi OpenSSL versiyası və konfiqurasiyasını göstərir. Müdafiəçilər əsas diqqəti QUIC server limitlərinin konfiqurasiyasına, OpenSSL versiyalarının yenilənməsinə və asılı proqram təminatında (PostgreSQL, FreeRDP) sertifikat doğrulama mexanizmlərinin düzgün işləməsinə yönəltməlidir.

This vendor's CVEs3

This hub is built from skopnix's own reporting on OpenSSL: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.