Exposure of OpenSSL

Web server extensions
157
exposure score
68,993
sites use
0
exploited
9
critical
Vexday analysis

Com 152 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o OpenSSL apresenta um volume relevante de vulnerabilidades acumuladas, embora sua taxa de exploração ativa esteja abaixo da média geral do catálogo KEV — nenhuma de suas falhas consta atualmente no registro de vulnerabilidades exploradas pelo CISA. Ainda assim, o cenário exige atenção: o maior EPSS observado chega a 0,957, valor próximo ao limite máximo da escala, associado à CVE-2022-2068, o que indica altíssima probabilidade de exploração segundo os modelos preditivos. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), que pode resultar em condições de negação de serviço em implementações que dependem da biblioteca. As 8 CVEs de severidade crítica reforçam a necessidade de ciclos de atualização rigorosos em qualquer ambiente que utilize OpenSSL como componente de infraestrutura criptográfica.

CVEs

156 results
CVE-2026-27459HIGHpyOpenSSL DTLS cookie callback buffer overflowEPSS 0.7%CVE-2019-1552Windows builds with insecure path defaultsEPSS 0.7%CVE-2025-24898MEDIUMrust openssl ssl::select_next_proto use after freeEPSS 0.7%CVE-2026-8507CRITICALCrypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flawsEPSS 0.6%CVE-2026-9265CRITICALCrypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING pathEPSS 0.6%CVE-2026-7383HIGHPossible Heap Buffer Overflow in ASN.1 Multibyte String ConversionEPSS 0.6%CVE-2023-2975MEDIUMAES-SIV implementation ignores empty associated data entriesEPSS 0.6%CVE-2022-43507HIGHImproper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable EPSS 0.6%CVE-2026-45445HIGHAES-OCB IV Ignored on EVP_Cipher() PathEPSS 0.6%CVE-2024-13176MEDIUMTiming side-channel in ECDSA signature computationEPSS 0.6%CVE-2016-7056MEDIUMA timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 privaEPSS 0.6%CVE-2026-9076HIGHOut-of-Bounds Read in CMS Password-Based DecryptionEPSS 0.6%CVE-2026-42768LOWMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()EPSS 0.6%CVE-2026-42767MEDIUMNULL Pointer Dereference in CRMF EncryptedValue DecryptionEPSS 0.6%CVE-2024-2467MEDIUMPerl-crypt-openssl-rsa: side-channel attack in pkcs#1 v1.5 padding mode (marvin attack)EPSS 0.5%CVE-2024-31074HIGHObservable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via neEPSS 0.5%CVE-2026-42765HIGHNULL Dereference in Certificate Verification with OCSP CheckingEPSS 0.5%CVE-2026-22796MEDIUMASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() functionEPSS 0.5%CVE-2025-3416LOWRust-openssl: rust-openssl use-after-free in `md::fetch` and `cipher::fetch`EPSS 0.5%CVE-2026-42770LOWFFC-DH Peer Validation Uses Attacker-Supplied qEPSS 0.5%