Inefficient Algorithmic Complexity Affecting openssl package, versions [3.4.0,3.4.8)[3.5.0,3.5.9)[3.6.0,3.6.5)[4.0.1,4.0.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-OPENSSL-20537036
  • published6 Oct 2026
  • disclosed29 Sept 2026
  • creditSaku0512,Opal Wright

Introduced: 29 Sep 2026

NewCVE-2026-42772  (opens in a new tab)
CWE-407  (opens in a new tab)

How to fix?

Upgrade openssl to version 3.4.8, 3.5.9, 3.6.5, 4.0.3 or higher.

Overview

Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the QUIC stream reassembly, which holds fragments in a doubly linked list optimized for appends and searches it head to tail when a fragment arrives out of order. An attacker can consume CPU quadratically in the number of fragments by ordering stream frame offsets so each one requires a full traversal. This requires a completed handshake, the frames are protocol compliant and need little bandwidth, and the pressure is scoped to that connection.

CVSS Base Scores

version 4.0
version 3.1