Exposure of OpenSSL

Web server extensions
157
exposure score
68,993
sites use
0
exploited
9
critical
Vexday analysis

Com 152 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o OpenSSL apresenta um volume relevante de vulnerabilidades acumuladas, embora sua taxa de exploração ativa esteja abaixo da média geral do catálogo KEV — nenhuma de suas falhas consta atualmente no registro de vulnerabilidades exploradas pelo CISA. Ainda assim, o cenário exige atenção: o maior EPSS observado chega a 0,957, valor próximo ao limite máximo da escala, associado à CVE-2022-2068, o que indica altíssima probabilidade de exploração segundo os modelos preditivos. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), que pode resultar em condições de negação de serviço em implementações que dependem da biblioteca. As 8 CVEs de severidade crítica reforçam a necessidade de ciclos de atualização rigorosos em qualquer ambiente que utilize OpenSSL como componente de infraestrutura criptográfica.

CVEs

156 results
CVE-2024-33617HIGHInsufficient control flow management in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosureEPSS 0.4%CVE-2026-8721CRITICALCrypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLsEPSS 0.4%CVE-2025-69419HIGHOut of bounds write in PKCS12_get_friendlyname() UTF-8 conversionEPSS 0.4%CVE-2026-2673MEDIUMOpenSSL TLS 1.3 server may choose unexpected key agreement groupEPSS 0.4%CVE-2024-28885HIGHObservable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network aEPSS 0.4%CVE-2024-3296MEDIUMRust-openssl: timing based side-channel can lead to a bleichenbacher style attackEPSS 0.4%CVE-2025-66199MEDIUMTLS 1.3 CompressedCertificate excessive memory allocationEPSS 0.4%CVE-2026-42769MEDIUMTrust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdateEPSS 0.4%CVE-2026-45446MEDIUMIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modesEPSS 0.4%CVE-2026-41681HIGHrust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length checkEPSS 0.4%CVE-2026-34182CRITICALCMS AuthEnvelopedData Processing May Accept Forged MessagesEPSS 0.4%CVE-2023-53159MEDIUMThe openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.EPSS 0.3%CVE-2025-4575MEDIUMThe x509 application adds trusted use instead of rejected useEPSS 0.3%CVE-2026-28386CRITICALOut-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 SupportEPSS 0.3%CVE-2026-35188MEDIUMDouble-free When Checking OCSP Stapled ResponseEPSS 0.3%CVE-2024-9355MEDIUMGolang-fips: golang fips zeroed bufferEPSS 0.3%CVE-2026-41677LOWrust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized lengthEPSS 0.3%CVE-2026-41676HIGHrust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1EPSS 0.3%CVE-2026-41898HIGHrust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peerEPSS 0.3%CVE-2026-54876HIGHClient-Side Memory Leak in OCSP Response CheckingEPSS 0.3%