OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
OpenSSL patches high-severity DTLS flaw CVE-2026-84782 (CVSS 8.2) that can leak unencrypted heap memory or crash DTLS connections.
CVE-2026-84782 is a high-severity OpenSSL flaw where a DTLS handshake message resend during a paused larger message send can transmit mislabeled data containing heap memory as unencrypted handshake data, or crash on unmapped memory. Fixes are available in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8, while 3.0, 1.1.1 and 1.0.2 fixes are limited to premium support customers. CISA assigned CVSS 8.2 and listed exploitation as none. The September 29 releases also fix 13 other flaws, including moderate CVE-2026-84783 (crash in multithreaded TLS) and low CVE-2026-75806 (DTLS 1.2 AEAD connection reset).