VYPR

OpenSSL FIPS modules

by OpenSSL Project

Source repositories

CVEs (2)

  • CVE-2026-28386HigApr 7, 2026
    risk 0.42cvss 7.5epss 0.00

    Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to…

  • CVE-2025-66199MedJan 27, 2026
    risk 0.00cvss 5.9epss 0.00

    Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit. Impact summary: An attacker can cause per-connection memory allocations of up to…