OpenSSL Patches High-Severity Flaw Exposing Server Memory in Plaintext
OpenSSL has released security updates to address CVE-2026-84782, a critical vulnerability that can leak server memory in plaintext during DTLS handshakes.

The OpenSSL Project has issued urgent security updates to address a high-severity vulnerability, tracked as CVE-2026-84782, which allows for the leakage of server heap memory in plaintext during Datagram Transport Layer Security (DTLS) handshakes. This flaw, stemming from an out-of-bounds read in the DTLS handshake retransmission logic, can also lead to denial-of-service conditions by crashing affected processes.
DTLS is designed to provide TLS-like security over unreliable datagram transports, which often involves fragmenting messages and retransmitting data when packets are lost or delayed. The vulnerability arises when OpenSSL suspends a handshake message write because the transport layer cannot accept more data. If a retransmission timer then triggers a resend of an earlier handshake message while the write is still suspended, vulnerable versions of OpenSSL reuse internal buffer and position tracking. Crucially, they fail to reset the read offset to the beginning of the queued message. This can cause the retransmission to start at a stale position, potentially appending leftover data from a different message and reading beyond the allocated buffer.
The consequence of this out-of-bounds read is that adjacent heap contents can be sent to the connected peer as plaintext handshake data. The specific data leaked depends on the contents of the process's memory at the time of the exploit. In some cases, if the out-of-bounds read attempts to access an unmapped memory region, the process may terminate instead, allowing an attacker to trigger a denial-of-service condition. The OpenSSL Project classifies this weakness under CWE-125, indicating an out-of-bounds read.
Beyond the memory leakage, the vulnerability introduces a state-management problem. Even when retransmission begins at the correct offset, completing it while another handshake write is paused overwrites shared bookkeeping data necessary for resuming the original operation. Subsequent calls to OpenSSL functions like SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() can then encounter inconsistent states, leading to an abort, particularly in debug builds.
The OpenSSL Project has fixed this vulnerability by ensuring the retransmission read position is reset before resending a message. Additionally, the code now skips retransmission entirely while a handshake write remains suspended, deferring the operation until a later call resumes it. Importantly, the affected logic resides outside the OpenSSL FIPS module boundary, meaning FIPS modules are not impacted by this specific flaw.
Multiple branches of OpenSSL are affected by this vulnerability. These include OpenSSL 4.0 before 4.0.3, 3.6 before 3.6.5, 3.5 before 3.5.9, 3.4 before 3.4.8, 3.0 before 3.0.23, 1.1.1 before 1.1.1zj, and 1.0.2 before 1.0.2zs. Patches for the three oldest branches (1.0.2, 1.1.1, and 3.0) are exclusively available to premium support customers.
Administrators are urged to inventory all systems and applications utilizing OpenSSL's DTLS functionality, including appliances, embedded systems, and VPN products. Updates should be applied through operating system or product vendors. For maintained branches, upgrading to OpenSSL 4.0.3, 3.6.5, 3.5.9, or 3.4.8 resolves the issue. Supported customers should obtain the patched versions for older branches: 3.0.23, 1.1.1zj, or 1.0.2zs. It is crucial to note that applications may bundle their own copies of OpenSSL, meaning a system-level update might not cover all vulnerable instances.
The vulnerability was reported by Laurent Gaffie of Secorizon on August 17, 2026, with the correction developed by Ryan Hooper. The release of OpenSSL 4.0.3 also includes fixes for 13 other vulnerabilities related to X.509 processing, QUIC, CMP, DTLS, SM2, and elliptic-curve operations, underscoring the importance of applying this security update promptly.