Skip to content
OpenSSL Vulnerabilities Impact HCL VersionVault and DevOps Tools

OpenSSL Vulnerabilities Impact HCL VersionVault and DevOps Tools

First seen 30 Sep 2026, 00:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 00:06 UTC

Multiple vulnerabilities in OpenSSL have been disclosed, affecting HCL VersionVault and HCL DevOps Code ClearCase. Key vulnerabilities include CVE-2025-11187, which may lead to stack buffer overflow or NULL pointer dereference, and CVE-2025-66199, which allows large buffer allocation without size checks. Other notable vulnerabilities include CVE-2025-22795 and CVE-2025-22796, both leading to denial of service through malformed PKCS#12 and PKCS#7 data processing. The vulnerabilities were reported by the OpenSSL Project, with CVSS scores ranging from 5.3 to 6.1, indicating medium severity. Users of affected systems are advised to apply patches as they become available. The OpenSSL 4.0.3 release also addresses high-severity vulnerabilities, including CVE-2026-84782 and CVE-2026-84783, which were published on September 29, 2026. This highlights the ongoing need for vigilance in updating cryptographic libraries.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-01-15
CVE-2025-22795 published
Type confusion vulnerability in OpenSSL's PKCS#12 parsing disclosed, leading to denial of service.
Support.Hcl-Software
2025-01-27
CVE-2025-11187 and CVE-2025-66199 published
Two vulnerabilities disclosed, one allowing stack buffer overflow and another enabling large buffer allocation without checks.
Support.Hcl-Software
2025-04-17
CVE-2025-22796 published
ASN1_TYPE type confusion vulnerability in OpenSSL's PKCS#7 signature verification disclosed.
Support.Hcl-Software
2026-09-29
OpenSSL 4.0.3 released
New version released to fix 14 CVEs, including high-severity vulnerabilities affecting DTLS and X.509 processing.
Linuxiac
2026-09-29
CVE-2026-84782 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-29
CVE-2026-84783 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2025-11187 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed