Intel

AIKIDO-2026-877705

openssl is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-54874 Published 6 days ago

37

Low Risk

This Affects:

C++openssl
1.0.2 - 3.0.21
Fixed in 3.0.22
3.4.0 - 3.4.6
Fixed in 3.4.7
3.5.0 - 3.5.7
Fixed in 3.5.8
3.6.0 - 3.6.3
Fixed in 3.6.4
4.0.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

While a DTLS handshake is in progress, OpenSSL buffers a record that claims to belong to the next epoch by retaining the whole read buffer, about 16 kilobytes, instead of the record bytes. A peer can send many small records of that kind, up to the cap of 100 per connection, and force the endpoint to hold far more memory than the bytes on the wire, which can exhaust a DTLS server that accepts many associations. The fix stores only the record bytes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application uses DTLS.

Background info

openssl is vulnerable to Denial of Service (DoS) in versions 1.0.2 - 3.0.21, 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.

How to fix this

Upgrade the openssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform