Intel

AIKIDO-2026-341396

openssl is vulnerable to Improper Integrity Validation

Improper Integrity ValidationCVE-2026-75803 Published 6 days ago

37

Low Risk

This Affects:

C++openssl
3.0.0 - 3.0.21
Fixed in 3.0.22
3.4.0 - 3.4.6
Fixed in 3.4.7
3.5.0 - 3.5.7
Fixed in 3.5.8
3.6.0 - 3.6.3
Fixed in 3.6.4
4.0.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

EVP_Cipher() finalizes ChaCha20-Poly1305 and AES-OCB decryption in one call and is expected to check the authentication tag. An empty ciphertext skips that tag check, so the call can return success for a tag that was never verified and the application can accept a forged empty message. The fix checks the tag on the empty ciphertext path before it reports success.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application calls EVP_Cipher() for ChaCha20-Poly1305 or AES-OCB.

Background info

openssl is vulnerable to Improper Integrity Validation in versions 3.0.0 - 3.0.21, 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.

How to fix this

Upgrade the openssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform