| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| openssl-3.5.9.tar.gz | 2026-09-29 | 53.3 MB | |
| openssl-3.5.9.tar.gz.asc | 2026-09-29 | 931 Bytes | |
| openssl-3.5.9.tar.gz.sha1 | 2026-09-29 | 63 Bytes | |
| openssl-3.5.9.tar.gz.sha256 | 2026-09-29 | 87 Bytes | |
| OpenSSL 3.5.9 source code.tar.gz | 2026-09-29 | 53.5 MB | |
| OpenSSL 3.5.9 source code.zip | 2026-09-29 | 57.1 MB | |
| README.md | 2026-09-29 | 2.7 kB | |
| Totals: 7 Items | 163.8 MB | 0 | |
OpenSSL 3.5.9 is a security patch release. The most severe CVE fixed in this release is High.
This release incorporates the following bug fixes and mitigations:
-
Fixed DTLS retransmissions of handshake messages from a stale buffer offset. (CVE-2026-84782)
-
Fixed excessive memory allocation in relative CRLDP processing. (CVE-2026-35189)
-
Fixed QUIC unvalidated amplification credit may be over-accounted. (CVE-2026-35191)
-
Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. (CVE-2026-42772)
-
Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. (CVE-2026-54872)
-
Fixed QUIC
STREAMfragment metadata DoS. (CVE-2026-54873) -
Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. (CVE-2026-54875)
-
Fixed out-of-bounds access after
SSL_set_SSL_CTX()during a handshake. (CVE-2026-72897) -
Fixed QUIC connection-level flow control was not enforced for streams. (CVE-2026-75804)
-
Fixed a NULL pointer dereference in CMP client revocation response handling. (CVE-2026-75805)
-
Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. (CVE-2026-75806)
-
Fixed a timing side-channel in SM2 signature generation. (CVE-2026-77696)
-
Fixed an unbounded
RETIRE_CONNECTION_IDbacklog in QUIC stack implementation. (CVE-2026-84784) -
Fixed a bug where
EVP_DecryptFinal()incorrectly reported a stale success on AES-SIV authentication failure.