| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| openssl-4.0.2.tar.gz | 2026-08-25 | 55.2 MB | |
| openssl-4.0.2.tar.gz.asc | 2026-08-25 | 931 Bytes | |
| openssl-4.0.2.tar.gz.sha1 | 2026-08-25 | 63 Bytes | |
| openssl-4.0.2.tar.gz.sha256 | 2026-08-25 | 87 Bytes | |
| OpenSSL 4.0.2 source code.tar.gz | 2026-08-25 | 55.3 MB | |
| OpenSSL 4.0.2 source code.zip | 2026-08-25 | 59.1 MB | |
| README.md | 2026-08-25 | 2.4 kB | |
| Totals: 7 Items | 169.6 MB | 16 | |
OpenSSL 4.0.2 is a security patch release. The most severe CVE fixed in this release is Moderate.
This release incorporates the following bug fixes and mitigations:
-
Fixed QUIC server being able to trigger double free when processing
INITIALpacket. (CVE-2026-18798) -
Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)
-
Fixed invalid pointer dereference in CMP server via crafted
protectionAlg. (CVE-2026-63076) -
Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)
-
Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)
-
Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)
-
Fixed client-side memory leak in OCSP response checking. (CVE-2026-54876)
-
Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)
-
Fixed CMP indefinite cache growth of
extraCerts. (CVE-2026-63074) -
Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)
-
Fixed possibility of AEAD forgeries with empty ciphertext when using
EVP_Cipher(). (CVE-2026-75803) -
Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.