Download Latest Version OpenSSL 4.0.3 source code.zip (59.2 MB) Google Add to Preferred Sources
Home / openssl-4.0.2
Name Modified Size InfoDownloads / Week
Parent folder
openssl-4.0.2.tar.gz 2026-08-25 55.2 MB
openssl-4.0.2.tar.gz.asc 2026-08-25 931 Bytes
openssl-4.0.2.tar.gz.sha1 2026-08-25 63 Bytes
openssl-4.0.2.tar.gz.sha256 2026-08-25 87 Bytes
OpenSSL 4.0.2 source code.tar.gz 2026-08-25 55.3 MB
OpenSSL 4.0.2 source code.zip 2026-08-25 59.1 MB
README.md 2026-08-25 2.4 kB
Totals: 7 Items   169.6 MB 16

OpenSSL 4.0.2 is a security patch release. The most severe CVE fixed in this release is Moderate.

This release incorporates the following bug fixes and mitigations:

  • Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798)

  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)

  • Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)

  • Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)

  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)

  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)

  • Fixed client-side memory leak in OCSP response checking. (CVE-2026-54876)

  • Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)

  • Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)

  • Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)

  • Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)

  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

Source: README.md, updated 2026-08-25