High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

https://www.securityweek.com/wp-content/uploads/2025/10/OpenSSL-communications-traffic.jpg

The developers of the OpenSSL and WolfSSL open source cryptographic libraries announced patches for roughly a dozen vulnerabilities each, including high-severity flaws.

Of the 14 vulnerabilities fixed in OpenSSL, one has been assigned a high severity rating. Tracked as CVE-2026-84782, it could allow a remote peer to obtain fragments of heap memory or crash applications that use Datagram TLS (DTLS), a protocol commonly found in VPNs, VoIP and IoT products.

The flaw is triggered during the DTLS handshake, when OpenSSL retransmits a message while sending another one is stalled. This can cause leftover heap data to be sent to the other party in plaintext. If the read reaches unmapped memory, the application crashes, resulting in a denial-of-service (DoS) condition.

The issue has a CVSS score of 8.2 and can be exploited over the network without authentication or user interaction.

The latest OpenSSL releases also fix a medium-severity vulnerability identified...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more