Download Latest Version OpenSSL 4.0.3 source code.zip (59.2 MB) Google Add to Preferred Sources
Home / openssl-3.4.8
Name Modified Size InfoDownloads / Week
Parent folder
openssl-3.4.8.tar.gz < 23 hours ago 18.4 MB
openssl-3.4.8.tar.gz.asc < 23 hours ago 931 Bytes
openssl-3.4.8.tar.gz.sha1 < 23 hours ago 63 Bytes
openssl-3.4.8.tar.gz.sha256 < 23 hours ago 87 Bytes
OpenSSL 3.4.8 source code.tar.gz < 24 hours ago 18.6 MB
OpenSSL 3.4.8 source code.zip < 24 hours ago 21.9 MB
README.md < 24 hours ago 2.4 kB
Totals: 7 Items   58.9 MB 0

OpenSSL 3.4.8 is a security patch release. The most severe CVE fixed in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782)

  • Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189)

  • Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772)

  • Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872)

  • Fixed QUIC STREAM fragment metadata DoS. (CVE-2026-54873)

  • Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875)

  • Fixed out-of-bounds access after SSL_set_SSL_CTX() during a handshake. (CVE-2026-72897)

  • Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804)

  • Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805)

  • Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806)

  • Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696)

  • Fixed an unbounded RETIRE_CONNECTION_ID backlog in QUIC stack implementation. (CVE-2026-84784)

Source: README.md, updated 2026-09-29