Improper Validation of Specified Quantity in Input Affecting openssl package, versions [1.1.1q,3.4.8)[3.5.0,3.5.9)[3.6.0,3.6.5)[4.0.1,4.0.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.39% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-OPENSSL-20536999
  • published6 Oct 2026
  • disclosed29 Sept 2026
  • creditMounir Idrassi

Introduced: 29 Sep 2026

NewCVE-2026-75806  (opens in a new tab)
CWE-1284  (opens in a new tab)

How to fix?

Upgrade openssl to version 3.4.8, 3.5.9, 3.6.5, 4.0.3 or higher.

Overview

Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input in the DTLS 1.2 record layer, which passes the record length to the cipher before checking that it covers the explicit IV and authentication tag, so an undersized record raises a fatal internal_error rather than an authentication failure. An attacker can tear down an established DTLS association without holding any key, by routing one undersized AEAD record to it. This requires knowledge of an existing association to route the datagram to, and the effect is limited to that association.

CVSS Base Scores

version 4.0
version 3.1