Search CVE reports


Toggle filters

11 – 20 of 146 results


CVE-2026-54875

Low priority

Some fixes available 1 of 4

Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-54872

Low priority

Some fixes available 8 of 18

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-35191

Low priority

Some fixes available 1 of 4

Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-35189

Low priority

Some fixes available 8 of 18

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-75803

Low priority

Some fixes available 4 of 9

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Vulnerable Vulnerable Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-63076

Medium priority

Some fixes available 4 of 9

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Vulnerable Vulnerable Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-63075

Low priority

Some fixes available 1 of 5

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-63074

Low priority

Some fixes available 4 of 9

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-63073

Low priority

Some fixes available 1 of 5

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-63072

Medium priority

Some fixes available 9 of 18

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages