logo

Security Advisory for OpenSSL Vulnerabilities

ID: 4a1606c6-1682-58ed-9382-a1a66df78b44

STIX ID: report--4a1606c6-1682-58ed-9382-a1a66df78b44

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

OpenSSL versions 3.0.0 through 3.0.6 contain two high-severity X.509 email-address parsing buffer overflow vulnerabilities (CVE-2022-3786 and CVE-2022-3602) that can cause crashes and potentially remote code execution; OpenSSL 3.0.7 contains the fixes. The advisory details affected versions, exploitation scenarios (malicious server or client certs during TLS handshakes), available mitigations (upgrade, disable client auth, vendor patches), notes a public PoC exists but no confirmed in-the-wild exploits, and describes how Zscaler’s cloud TLS inspection and posture controls help mitigate risk for customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.