Skip to content

Multiple OpenSSL Vulnerabilities Exposes Sensitive Data in RSA KEM Handling

Cybersecuritynews Guru Baran April 8, 2026

OpenSSL has released a broad April 2026 security update that fixes seven vulnerabilities across supported branches, led by CVE-2026-31790, a moderate-severity flaw in RSA KEM RSASVE encapsulation that can expose uninitialized memory to a malicious peer. The advisory directs users of vulnerable 3.x releases to move to OpenSSL 3.0.20, 3.3.7, 3.4.5, 3.5.6, or 3.6.2, depending […]

Extracted Entities

Tools (1)