logo

Multiple OpenSSL Vulnerabilities Exposes Sensitive Data in RSA KEM Handling

ID: eeceaa5f-170b-5f3c-a4f2-025226f2da7c

STIX ID: report--eeceaa5f-170b-5f3c-a4f2-025226f2da7c

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2026-04-08

Date Updated: 2026-05-05

Author: Guru Baran

...
...

OpenSSL released an April 2026 update fixing seven vulnerabilities across supported 3.x branches, led by CVE-2026-31790 — a moderate RSA KEM (RSASVE) encapsulation flaw that can return uninitialized ciphertext bytes to a peer and potentially leak sensitive memory. The advisory identifies affected 3.x and FIPS module versions, recommends upgrading to specific patched releases and adding explicit public-key validation (EVP_PKEY_public_check()/EVP_PKEY_public_check_quick()), and describes several additional low-severity issues that mainly enable denial-of-service in edge cases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.