Improper Validation of Integrity Check Value Affecting openssl package, versions [3.0.0-alpha1, 3.0.22)[3.4.0-alpha1, 3.4.7)[3.5.0-alpha1, 3.5.8)[3.6.0-alpha1, 3.6.4)[4.0.0-alpha1, 4.0.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.12% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-OPENSSL-19267453
  • published26 Aug 2026
  • disclosed25 Aug 2026
  • creditBilly Brumley (Rochester Institute of Technology)

Introduced: 25 Aug 2026

NewCVE-2026-75803  (opens in a new tab)
CWE-354  (opens in a new tab)

How to fix?

Upgrade openssl to version 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Validation of Integrity Check Value in the chacha20_poly1305_cipher and aes_ocb_cipher implementations under providers/implementations/ciphers/. An attacker can forge messages by supplying an empty ciphertext and a bad tag, then invoking EVP_Cipher(ctx, out, NULL, 0) so the operation returns success without checking the tag. Applications that treat that successful return as proof of integrity may accept tampered ChaCha20-Poly1305 or AES-OCB messages.

CVSS Base Scores

version 4.0
version 3.1