logo

OpenSSL vulnerabilities: Everything you need to know

ID: 768f7e60-66d5-5bf8-8868-5e836641fd42

STIX ID: report--768f7e60-66d5-5bf8-8868-5e836641fd42

Feed Name: Wiz Blog

Threat Score
50/100

Date Published: 2022-10-29

Date Updated: 2026-05-01

...
...

**TL;DR:** OpenSSL disclosed two High-severity vulnerabilities (CVE-2022-3602 and CVE-2022-3786) in the X.509/punycode handling of OpenSSL 3.x that can cause buffer overflows and potentially remote code execution; exploitation is constrained (servers must use mTLS or clients must connect to attacker-controlled servers), available public POCs primarily cause crashes, only ~1.5% of OpenSSL instances are impacted in the analyzed cloud environments, and the vendor recommends upgrading to OpenSSL 3.0.7 while prioritizing internet-facing and mission-critical assets for patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.