we_are_coded.by CODE · The world, decoded
БГ
OpenSSL

OpenSSL patches 14 holes at once, and the worst one can send a chunk of memory to the other side

OpenSSL Security Advisory · event date: 29 September 2026Security

OpenSSL's advisory of 29 September covers 14 vulnerabilities: one high, one moderate and 12 low. The high one is in DTLS and can leak a chunk of memory as ordinary handshake data or crash the process. No active exploitation is reported.

In short
  • CVE-2026-84782 affects every supported branch from 1.0.2 to 4.0.
  • Free fixes exist for 4.0, 3.6, 3.5 and 3.4. For 3.0, 1.1.1 and 1.0.2 they are for premium support only.
  • Two of the low-severity holes were also reported by Trail of Bits in collaboration with OpenAI.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Two of the fourteen holes were reported by Trail of Bits "in collaboration with OpenAI". It says so in the advisory itself, among the low-severity ones.

It is not the headline, but it is the direction. OpenAI's name now appears in the list of finders for the cryptographic library that a huge share of servers stand on. Whether and how a model helped, the advisory does not say.

The facts: on 29 September 2026 OpenSSL published a security advisory with 14 CVEs. The high one is CVE-2026-84782: in DTLS, retransmitting a handshake message while another write is suspended part-way through can read past the buffer and send a chunk of memory to the peer as plaintext data, or crash the process. OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are affected; the fixes are 4.0.3, 3.6.5, 3.5.9 and 3.4.8, while 3.0.23, 1.1.1zj and 1.0.2zs are for premium support customers only. The moderate one is CVE-2026-84783, a use-after-free in the X.509 extension cache under concurrent use by several threads; it affects only 4.0 and can crash a multi-threaded TLS client or a server that requests client certificates. The remaining 12 are low severity, several of them in QUIC. The affected code is outside the FIPS module boundary. Two of the low ones, CVE-2026-42772 and CVE-2026-72897, were reported, alongside other researchers, by Trail of Bits in collaboration with OpenAI. Versions 3.1, 3.2 and 3.3 are out of support and were not analysed. The advisory does not mention active exploitation.

The practical part is duller than the news. DTLS is not the ordinary TLS that opens a website. VPNs, voice and video connections and devices that talk over UDP use it. If you do not know whether yours does, that is today's task.

High severity, and no active attack reported. That is the window in which you update calmly.

A separate issue is the 3.0 branch, still sitting on plenty of servers. There is no free fix for it in this advisory: 3.0.23 is for premium support only. And 3.1, 3.2 and 3.3 were not checked at all, because they are out of support.

Check which OpenSSL sits in your images and containers, not just on the host. You update on the next deploy, not next quarter.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→OpenSSL Security Advisory, 29.09.2026
Original: https://wearecoded.com/en/articles/openssl-14-dupki-dtls-cve-2026-84782.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news