VDB
JLSEC-2026-227
JLSEC-2026-227
PUBLISHED
CVSS 8.699999809265137 HIGH
openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Julia | OpenSSL_jll | 0, 0 |
| Julia | libnode_jll | 0, 0 |
| Julia | Openresty_jll | 0, 0 |
Timeline
- Apr 27, 2026 CVE Published
- Apr 27, 2026 CVE Updated
- May 1, 2026 Distribution Patch
References
- http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html url
- http://seclists.org/fulldisclosure/2022/May/33 url
- http://seclists.org/fulldisclosure/2022/May/35 url
- http://seclists.org/fulldisclosure/2022/May/38 url
- https://cert-portal.siemens.com/productcert/html/ssa-019200.html url
- https://cert-portal.siemens.com/productcert/html/ssa-028723.html url
- https://cert-portal.siemens.com/productcert/html/ssa-108696.html url
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html url
- https://cert-portal.siemens.com/productcert/html/ssa-712929.html url
- https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf url
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65 url
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83 url
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246 url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=3118eb64934499d93db3230748a452351d1d9a65 url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=380085481c64de749a6dd25cdf0bcf4360b30f83 url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a466912611aa6cbdf550cd10601390e587451246 url
- https://github.com/advisories/GHSA-x3mh-jvjw-3xwx url
- https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html url
- https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ url
…and 29 more