Critical Security Patches Released for OpenSSL and WolfSSL: Latest Updates

www.news4hackers.com-critical-security-patches-released-for-openssl-and-wolfssl-latest-updates-critical-security-patches-released-for-openssl-and-wolfssl-latest-updates

Developers of the OpenSSL and WolfSSL open-source cryptographic libraries have released updates addressing approximately a dozen vulnerabilities each, including several high-severity issues.

OpenSSL Patches

The OpenSSL patches resolve 14 flaws, one of which carries a high severity rating. Designated CVE-2026-84782, this vulnerability could enable a remote peer to access fragments of heap memory or trigger application crashes in systems utilizing Datagram TLS (DTLS). DTLS is commonly employed in virtual private networks (VPNs), voice-over IP (VoIP) services, and Internet of Things (IoT) devices.

CVE-2026-84782

The flaw arises during the DTLS handshake process when OpenSSL retransmits a message while another transmission is delayed, potentially exposing leftover heap data in plaintext. If the affected application reads unmapped memory, it may crash, resulting in a denial-of-service (DoS) condition. The vulnerability has a CVSS score of 8.2 and can be exploited over the network without requiring authentication or user interaction.

CVE-2026-84783

A medium-severity flaw, CVE-2026-84783, was also addressed in the latest OpenSSL releases. This issue allows an unauthenticated remote peer to crash a multi-threaded TLS client, leading to a DoS scenario. The remaining vulnerabilities in OpenSSL are categorized as low severity, primarily causing DoS conditions through excessive resource consumption, process crashes, or termination of DTLS 1.2 connections.

WolfSSL Vulnerabilities

WolfSSL developers issued version 5.9.4 on September 25, incorporating fixes for 11 vulnerabilities, three of which are classified as high severity. These flaws permit attackers to bypass peer authentication under specific configurations.

CVE-2026-93302

CVE-2026-93302 stems from WolfSSL’s failure to validate public keys when matching certificates against trusted peers. A malicious server aware of a client’s trusted certificate authorities (CAs) could present a forged CA clone to circumvent authentication. Affected implementations include those integrated with Nginx, HAProxy, Stunnel, and Apache httpd.

CVE-2026-89102

CVE-2026-89102 allows an attacker with access to any certificate and its private key that chains to a trusted CA to forge certificates for arbitrary identities.

CVE-2026-89136

CVE-2026-89136 enables a malicious server to bypass authentication on clients with Raw Public Key (RPK) support by selecting an RPK certificate type not requested by the client.

Four medium-severity issues involve certificate validation flaws and handshake sequencing errors, which could permit attackers to bypass name constraints, inject unverified CAs into shared certificate managers, or complete TLS 1.2 or DTLS 1.2 handshakes on behalf of legitimate servers. Low-severity bugs in WolfSSL include a use-after-free vulnerability during connection termination, skipped Certificate Revocation List (CRL) checks, acceptance of certificates with invalid signatures, and server impersonation risks. Most of these require specific configurations or legacy API usage to exploit.



About Author

en_USEnglish