AppBundler
JLSEC-2026-1156High 7.5UpstreamIssue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes …JLSEC-2026-1155High 8.1UpstreamIssue summary: A signed integer overflow when sizing the destination buffer for Unicode o…JLSEC-2026-1145High 8.8UpstreamIssue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-af…JLSEC-2026-1144Medium 4.8UpstreamIssue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) misha…JLSEC-2026-1143High 7.5UpstreamIssue summary: When an application drives an AES-OCB context through the public EVP_Ciphe…JLSEC-2026-1142Low 3.7UpstreamIssue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the…JLSEC-2026-1141Medium 5.3UpstreamIssue Summary: An error in the callback used to verify the certificate provided in a Root…JLSEC-2026-1140Low 3.7UpstreamIssue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbach…JLSEC-2026-1139Medium 5.9UpstreamIssue summary: An attacker-controlled CMP (Certificate Management Protocol) server could …JLSEC-2026-1138Medium 5.9UpstreamIssue summary: A specially crafted password-encrypted CMS message can trigger a NULL poin…JLSEC-2026-1137High 7.5UpstreamIssue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL p…JLSEC-2026-1136High 7.5UpstreamIssue summary: Remote peer may exhaust heap memory of the QUIC server or client by floodi…JLSEC-2026-1135Critical 9.1UpstreamIssue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficien…JLSEC-2026-1134High 7.4UpstreamIssue Summary: The PKCS#12 file processing fails to perform sufficient input validation f…JLSEC-2026-1133High 7.5UpstreamIssue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element who…JLSEC-2026-277High 7.5UpstreamIssue summary: Applications using RSASVE key encapsulation to establish a secret encrypti…JLSEC-2026-276Critical 9.8UpstreamIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string…JLSEC-2026-275High 7.5UpstreamNo summary availableJLSEC-2026-274High 7.5UpstreamIssue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeReci…JLSEC-2026-273High 7.5UpstreamNo summary availableJLSEC-2026-272High 8.1UpstreamNo summary availableJLSEC-2026-271Medium 6.5UpstreamIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key…