OpenSSL 4.0.2 Patches Multiple Security Flaws Across Core Components
Open Source For You, Wednesday, August 26th, 2026
OpenSSL 4.0.2 fixes a heap buffer overflow and memory exhaustion issues across core cryptographic components.
OpenSSL has released version 4.0.2, addressing multiple security flaws across core components including CMS, DTLS, OCSP, CMP, QUIC, and AEAD.
Key fixes include a heap buffer overflow in CMS key unwrapping and defects causing excessive memory consumption, plus authentication-tag problems for empty ciphertexts in CCM-mode ciphers.
Concurrent releases for the maintained 3.x branches - 3.6.4, 3.5.8, 3.4.7, and 3.0.22 - carry additional security and bug fixes. Organizations running OpenSSL are advised to patch immediately.