The OpenSSL project reports:
- DTLS Retransmits Handshake Messages From a Stale Buffer Offset (CVE-2026-84782) [High]
- Use-After-Free in X.509 Extension Cache Under Concurrent Use (CVE-2026-84783) [Moderate]
- Excessive Memory Allocation in Relative CRLDP Processing (CVE-2026-35189) [Low]
- QUIC Unvalidated Amplification Credit may be Over Accounted (CVE-2026-35191) [Low]
- Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC (CVE-2026-42772) [Low]
- Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves (CVE-2026-54872) [Low]
- QUIC STREAM Fragment Metadata DoS (CVE-2026-54873) [Low]
- Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V (CVE-2026-54875) [Low]
- Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake (CVE-2026-72897) [Low]
- QUIC Connection-Level Flow Control is Not Enforced for Streams (CVE-2026-75804) [Low]
- NULL Pointer Dereference in CMP Client Revocation Response Handling (CVE-2026-75805) [Low]
- Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS (CVE-2026-75806) [Low]
- Timing Side-Channel in SM2 Signature Generation (CVE-2026-77696) [Low]
- QUIC: Unbounded RETIRE_CONNECTION_ID Backlog (CVE-2026-84784) [Low]