LobstersJun 10, 2026, 1:08 AM3

CVE-2026-45447: Heap Use-After-Free in the PKCS7_verify() Function

OpenSSL released fixes for three critical vulnerabilities affecting ASN.1 decoding, PKCS#12 file validation, and CMS message processing that could enable certificate forgery, key compromise, and integrity bypass attacks.

21 in 2561222026-01-27
Read original at Lobsters

0 comments

Sign in to join the discussion.