Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.

Openresty_jll

Fix
Severity
JLSEC-2026-1156High 7.5UpstreamIssue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes …JLSEC-2026-1155High 8.1UpstreamIssue summary: A signed integer overflow when sizing the destination buffer for Unicode o…JLSEC-2026-1145High 8.8UpstreamIssue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-af…JLSEC-2026-1144Medium 4.8UpstreamIssue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) misha…JLSEC-2026-1143High 7.5UpstreamIssue summary: When an application drives an AES-OCB context through the public EVP_Ciphe…JLSEC-2026-1142Low 3.7UpstreamIssue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the…JLSEC-2026-1141Medium 5.3UpstreamIssue Summary: An error in the callback used to verify the certificate provided in a Root…JLSEC-2026-1140Low 3.7UpstreamIssue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbach…JLSEC-2026-1139Medium 5.9UpstreamIssue summary: An attacker-controlled CMP (Certificate Management Protocol) server could …JLSEC-2026-1138Medium 5.9UpstreamIssue summary: A specially crafted password-encrypted CMS message can trigger a NULL poin…JLSEC-2026-1137High 7.5UpstreamIssue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL p…JLSEC-2026-1136High 7.5UpstreamIssue summary: Remote peer may exhaust heap memory of the QUIC server or client by floodi…JLSEC-2026-1135Critical 9.1UpstreamIssue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficien…JLSEC-2026-1134High 7.4UpstreamIssue Summary: The PKCS#12 file processing fails to perform sufficient input validation f…JLSEC-2026-1133High 7.5UpstreamIssue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element who…JLSEC-2026-277High 7.5UpstreamIssue summary: Applications using RSASVE key encapsulation to establish a secret encrypti…JLSEC-2026-276Critical 9.8UpstreamIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string…JLSEC-2026-275High 7.5UpstreamNo summary availableJLSEC-2026-274High 7.5UpstreamIssue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeReci…JLSEC-2026-273High 7.5UpstreamNo summary availableJLSEC-2026-272High 8.1UpstreamNo summary availableJLSEC-2026-271Medium 6.5UpstreamIssue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key…JLSEC-2026-480Medium 5.5Upstreamzlib before 1.3.2 allows CPU consumption via `crc32_combine64` and `crc32_combine_gen64` …JLSEC-2026-270Medium 5.3UpstreamIssue summary: A type confusion vulnerability exists in the signature verification of sig…JLSEC-2026-269Medium 5.5UpstreamIssue summary: An invalid or NULL pointer dereference can happen in an application proces…JLSEC-2026-265High 7.5UpstreamIssue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference…JLSEC-2026-264High 7.5UpstreamIssue summary: A type confusion vulnerability exists in the TimeStamp Response verificati…JLSEC-2026-263High 7.4UpstreamIssue summary: Calling `PKCS12_get_friendlyname()` function on a maliciously crafted PKCS…JLSEC-2026-262Medium 4.0UpstreamIssue summary: When using the low-level OCB API directly with AES-NI or<br>other...JLSEC-2026-261Medium 4.7UpstreamIssue summary: Writing large, newline-free data into a BIO chain using the line-buffering…JLSEC-2026-256High 8.8UpstreamIssue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parame…JLSEC-2026-266High 7.5UpstreamNo summary availableJLSEC-2026-248Medium 4.1UpstreamIssue summary: A timing side-channel which could potentially allow recovering the private…JLSEC-2026-251High 7.5UpstreamIssue summary: Calling the OpenSSL API function `SSL_free_buffers` may cause memory to be…JLSEC-2026-254Medium 4.3UpstreamIssue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit v…JLSEC-2026-252Critical 9.1UpstreamIssue summary: Calling the OpenSSL API function `SSL_select_next_proto` with an empty sup…JLSEC-2026-249Medium 5.9UpstreamIssue summary: Some non-default TLS server configurations can cause unbounded memory grow…JLSEC-2026-247Medium 5.5UpstreamNull pointer dereference in PKCS12 parsingJLSEC-2026-244Medium 5.3UpstreamIssue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.…JLSEC-2026-479Critical 9.8UpstreamNo summary availableJLSEC-2026-3High 7.5UpstreamThe HTTP/2 protocol allows a denial of service (server resource consumption) because requ…JLSEC-2026-242High 7.8UpstreamIssue summary: The POLY1305 MAC (message authentication code) implementation contains a b…JLSEC-2026-241Medium 5.3UpstreamIssue summary: Checking excessively long DH keys or parameters may be very slow.JLSEC-2026-239Medium 6.5UpstreamIssue summary: Processing some specially crafted ASN.1 object identifiers or data contain…JLSEC-2026-237Medium 5.3UpstreamThe function `X509_VERIFY_PARAM_add0_policy()` is documented to implicitly enable the cer…JLSEC-2026-236Medium 5.3UpstreamApplications that use a non-default option when verifying certificates may be vulnerable …JLSEC-2026-235High 7.5UpstreamA security vulnerability has been identified in all supported versionsJLSEC-2026-234High 7.4UpstreamVulnerable OpenSSL included in cryptography wheelsJLSEC-2026-233High 7.5Upstreamopenssl-src vulnerable to Use-after-free following `BIO_new_NDEF`JLSEC-2026-232High 7.5Upstreamopenssl-src contains Double free after calling `PEM_read_bio_ex`JLSEC-2026-231Medium 5.9Upstreamopenssl-src subject to Timing Oracle in RSA DecryptionJLSEC-2026-478Critical 9.8UpstreamNo summary availableJLSEC-2026-230Medium 5.3UpstreamAES OCB fails to encrypt some bytesJLSEC-2026-229High 7.3UpstreamIn addition to the `c_rehash` shell command injection identified in CVE-2022-1292, furthe…JLSEC-2026-228High 7.3UpstreamThe `c_rehash` script does not properly sanitise shell metacharacters to prevent command …JLSEC-2026-477High 7.5UpstreamNo summary availableJLSEC-2026-227High 7.5Upstreamopenssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificatesJLSEC-2026-226Medium 5.9UpstreamThere is a carry propagation bug in the MIPS32 and MIPS64 squaring procedureJLSEC-2026-225High 7.4UpstreamRead buffer overruns processing ASN.1 stringsJLSEC-2026-222Medium 5.9UpstreamInteger Overflow in openssl-srcJLSEC-2026-221High 7.5UpstreamInteger Overflow in openssl-srcJLSEC-2026-220Medium 5.9UpstreamThe X.509 GeneralName type is a generic type for representing different types of namesJLSEC-2026-177Medium 5.3UpstreamNo summary availableJLSEC-2026-216Medium 5.3UpstreamThere is an overflow bug in the `x64_64` Montgomery squaring procedure used in exponentia…