Exposure of OpenSSL

Web server extensions
157
exposure score
68,993
sites use
0
exploited
9
critical
Vexday analysis

Com 152 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o OpenSSL apresenta um volume relevante de vulnerabilidades acumuladas, embora sua taxa de exploração ativa esteja abaixo da média geral do catálogo KEV — nenhuma de suas falhas consta atualmente no registro de vulnerabilidades exploradas pelo CISA. Ainda assim, o cenário exige atenção: o maior EPSS observado chega a 0,957, valor próximo ao limite máximo da escala, associado à CVE-2022-2068, o que indica altíssima probabilidade de exploração segundo os modelos preditivos. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), que pode resultar em condições de negação de serviço em implementações que dependem da biblioteca. As 8 CVEs de severidade crítica reforçam a necessidade de ciclos de atualização rigorosos em qualquer ambiente que utilize OpenSSL como componente de infraestrutura criptográfica.

CVEs

156 results
CVE-2022-1343MEDIUMOCSP_basic_verify may incorrectly verify the response signing certificateEPSS 1.2%CVE-2026-31790HIGHIncorrect Failure Handling in RSA KEM RSASVE EncapsulationEPSS 1.2%CVE-2019-1547ECDSA remote timing attackEPSS 1.2%CVE-2017-16065openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16064node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2026-42764HIGHNULL Pointer Dereference in QUIC Server Initial Packet HandlingEPSS 1.2%CVE-2024-4603MEDIUMExcessive time spent checking DSA keys and parametersEPSS 1.1%CVE-2022-1434Incorrect MAC key used in the RC4-MD5 ciphersuiteEPSS 1.1%CVE-2026-28388HIGHNULL Pointer Dereference When Processing a Delta CRLEPSS 1.1%CVE-2026-34183HIGHUnbounded Memory Growth in the QUIC PATH_CHALLENGE HandlerEPSS 1.0%CVE-2026-28389HIGHPossible NULL Dereference When Processing CMS KeyAgreeRecipientInfoEPSS 1.0%CVE-2026-28390HIGHPossible NULL Dereference When Processing CMS KeyTransportRecipientInfoEPSS 1.0%CVE-2026-34180HIGHHeap Buffer Over-read in ASN.1 Content ParsingEPSS 1.0%CVE-2026-42766MEDIUMPossible NULL Dereference in Password-Based CMS DecryptionEPSS 1.0%CVE-2023-1255MEDIUMInput buffer over-read in AES-XTS implementation on 64 bit ARMEPSS 1.0%CVE-2023-4807HIGHPOLY1305 MAC implementation corrupts XMM registers on WindowsEPSS 0.9%CVE-2025-69421HIGHNULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex functionEPSS 0.8%CVE-2026-28387HIGHPotential Use-after-free in DANE Client CodeEPSS 0.8%CVE-2025-69420HIGHMissing ASN1_TYPE validation in TS_RESP_verify_response() functionEPSS 0.8%CVE-2025-15468MEDIUMNULL dereference in SSL_CIPHER_find() function on unknown cipher IDEPSS 0.7%