logo

Multiple OpenSSL Flaws Expose Sensitive Data in RSA KEM Handling

ID: c85bfc3a-f46c-516b-ada9-975568b55c54

STIX ID: report--c85bfc3a-f46c-516b-ada9-975568b55c54

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Divya

...
...

A newly disclosed moderate-severity OpenSSL vulnerability (CVE-2026-31790) in RSASVE encapsulation can cause RSA_public_encrypt errors to be misinterpreted as success, leading applications to return uninitialized ciphertext buffer contents and potentially leak sensitive memory. OpenSSL 3.x releases are affected; vendors have issued patches (specific 3.x versions listed) and recommend validating public keys with EVP_PKEY_public_check()/EVP_PKEY_public_check_quick() or upgrading to the provided patched releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.