# OpenSSL openssl-4.0.2 — OpenSSL 4.0.2 - Product: OpenSSL (https://whatsnew.fyi/product/openssl) - Vendor: OpenSSL Project - Date: 2026-08-25 - Version: openssl-4.0.2 - Original notes: https://github.com/openssl/openssl/releases/tag/openssl-4.0.2 - Permalink: https://whatsnew.fyi/product/openssl/releases/openssl-4.0.2 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Fixed QUIC server being able to trigger double free when processing INITIAL packet - **security** — Fixed heap buffer overflow in CMS key unwrapping - **security** — Fixed invalid pointer dereference in CMP server via crafted protectionAlg - **security** — Fixed unbounded memory growth in QUIC server incoming channel queue - **security** — Fixed RPK server signature algorithm selection being able to dereference a missing certificate - **security** — Fixed excessive memory use buffering DTLS records for a future epoch - **security** — Fixed client-side memory leak in OCSP response checking - **security** — Fixed untrusted Sender DN being used as a format string in CMP response validation - **security** — Fixed CMP indefinite cache growth of extraCerts - **security** — Fixed QUIC ACK-only packet retention being able to cause memory exhaustion - **security** — Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher() - **security** — Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode OpenSSL 4.0.2 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: * Fixed QUIC server being able to trigger double free when processing `INITIAL` packet. ([CVE-2026-18798]) * Fixed heap buffer overflow in CMS key unwrapping. ([CVE-2026-63072]) * Fixed invalid pointer dereference in CMP server via crafted `protectionAlg`. ([CVE-2026-63076]) * Fixed unbounded memory growth in QUIC server incoming channel queue. ([CVE-2026-14456]) * Fixed RPK server signature algorithm selection being able to dereference a missing certificate. ([CVE-2026-14457]) * Fixed excessive memory use buffering DTLS records for a future epoch. ([CVE-2026-54874]) * Fixed client-side memory leak in OCSP response checking. ([CVE-2026-54876]) * Fixed untrusted Sender DN being used as a format string in CMP response validation. ([CVE-2026-63073]) * Fixed CMP indefinite cache growth of `extraCerts`. ([CVE-2026-63074]) * Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. ([CVE-2026-63075]) * Fixed possibility of AEAD forgeries with empty ciphertext when using `EVP_Cipher()`. ([CVE-2026-75803]) * Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode. [CVE-2026-18798]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-18798 [CVE-2026-63072]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63072 [CVE-2026-63076]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63076 [CVE-2026-14456]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-14456 [CVE-2026-14457]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-14457 [CVE-2026-54874]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54874 [CVE-2026-54876]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-54876 [CVE-2026-63073]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63073 [CVE-2026-63074]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63074 [CVE-2026-63075]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-63075 [CVE-2026-75803]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-75803