VYPR

Security

by OpenSSL Project

CVEs (1)

  • CVE-2026-9076HigJun 9, 2026
    risk 0.42cvss 7.5epss

    Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). Impact summary: A heap buffer over-read may trigger a crash…