Multiple OpenSSL Vulnerabilities Exposes Sensitive Data in RSA KEM Handling
ID: eeceaa5f-170b-5f3c-a4f2-025226f2da7c
STIX ID: report--eeceaa5f-170b-5f3c-a4f2-025226f2da7c
Feed Name: cybersecurityNews.com
OpenSSL released an April 2026 update fixing seven vulnerabilities across supported 3.x branches, led by CVE-2026-31790 — a moderate RSA KEM (RSASVE) encapsulation flaw that can return uninitialized ciphertext bytes to a peer and potentially leak sensitive memory. The advisory identifies affected 3.x and FIPS module versions, recommends upgrading to specific patched releases and adding explicit public-key validation (EVP_PKEY_public_check()/EVP_PKEY_public_check_quick()), and describes several additional low-severity issues that mainly enable denial-of-service in edge cases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
