Skip to content

project

OpenSSL

OpenSSL is an open-source toolkit implementing TLS/SSL and general-purpose cryptography, providing the libssl/libcrypto libraries and a command-line tool.

Known aliases

  • libssl1.1
  • openssl
  • OpenSSL 1.1
  • OpenSSL 3
  • OpenSSL 3.5
  • openssl binary
  • openssl.exe
  • OpenSSL Project
  • OpenSSL Software Foundation
  • openssl_verify
  • PHP OpenSSL
  • s_client

Relationships

No evidence-backed relationships are recorded.

Current stories

security4 publishers

OpenSSL patches a DTLS flaw that sends heap memory to unauthenticated peers

OpenSSL patched 14 flaws, led by CVE-2026-84782, a CVSS 8.2 DTLS handshake bug that lets an unauthenticated remote peer pull fragments of heap memory. Only software that speaks DTLS is exposed, so VPN, VoIP and IoT products go first in the patch queue.

Perspective Coverage

4 publishers
Builder
Builder 40%
Operator
Operator 54%
Investor
Investor 6%

Reality

Evidence74
Adoption40
Hype gap+25
Incentives30
Confidence70
build1 publisher

Postgres 18.6 fails closed on PGP columns OpenSSL never actually encrypted

The 18.6 notes say a dump and restore is not required, then hand over three security entries that change defaults. Old pgcrypto messages stop decrypting by design, and third-party logical decoding plugins stop loading.

Publishers:postgresql.org

Reality

Evidence85
Adoption
Insufficient
Hype gap−15
Incentives25
Confidence80
build1 publisher

Node 26.8.2 bumps OpenSSL, undici and npm inside the runtime

Upgrading a Node 26 binary also upgrades the TLS library, the bundled HTTP client and the package manager. The 26.8.2 changelog names OpenSSL 3.5.8, undici 8.10.2 and npm 11.19.1 among its dependency commits.

Publishers:nodejs.org

Reality

Evidence78
Adoption20
Hype gap−8
Incentives32
Confidence70
build1 publisher

Node 24.21.0 swaps the bundled root certificates for NSS 3.126

The LTS patch also carries OpenSSL 3.5.8, six semver-minor additions including a faster net.BlockList, and three FIPS entries filed under one pull request, so the regression run costs more than a version bump usually does.

Publishers:nodejs.org

Reality

Evidence86
Adoption20
Hype gap−10
Incentives30
Confidence68
build1 publisher

Node 26.8.0 replaces its bundled root certificates with NSS 3.126

The certificate refresh ships as an ordinary commit with no semver-minor marker, so it reaches your hosts on image-rebuild cadence rather than through a patch channel. TracingChannel going stable is the other line worth reading twice.

Publishers:nodejs.org

Reality

Evidence76
Adoption12
Hype gap−8
Incentives30
Confidence70

Earlier coverage

  1. One slug, seven editions: the miniOrange SAML bug that makes published metadata an admin login

    Build · August 24, 2026 · 1 publisher

  2. Nine bundled CLIs, zero static links: an OpenSSL CVE becomes a file copy, and the parser is the bill

    Build · August 23, 2026 · 1 publisher

  3. Firmware CVE intake: the finding is almost never a zero-day, it is a five-year-old BusyBox

    Build · August 22, 2026 · 1 publisher

  4. A year of green backups hid 7 of 10 missing Android signing keys

    Build · August 17, 2026 · 1 publisher

  5. Every viewer hits your HLS key endpoint in the same second, and almost nobody tests it

    Build · August 17, 2026 · 1 publisher