OpenSSL maintainers released urgent security updates to address three newly discovered vulnerabilities affecting all supported versions of the widely used SSL/TLS library. The vulnerabilities, tracked as CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232, pose risks including key recovery, remote code execution, and denial-of-service attacks. One of the flaws, CVE-2025-9230, involves an out-of-bounds read and write in the CMS decryption process with password-based encryption (PWRI), which could lead to application crashes or memory corruption, potentially allowing attackers to execute arbitrary code. Although the use of PWRI is rare, the consequences of successful exploitation could be severe, prompting OpenSSL to rate the flaw as moderate in severity. FIPS modules are not affected by this vulnerability. Another vulnerability, CVE-2025-9231, is a timing side-channel issue in SM2 signature computations on 64-bit ARM platforms, which could enable attackers to recover private keys through precise timing measurements. While OpenSSL does not natively support SM2 keys in TLS, the risk remains for applications using SM2 signatures. The third flaw, CVE-2025-9232, details were not fully elaborated in the available sources, but it is included in the urgent patch set. OpenSSL has released patched versions 3.5.4, 3.4.3, 3.3.5, 3.2.6, 3.0.18, 1.0.2zm, and 1.1.1zd to address these vulnerabilities. Security experts and the OpenSSL Project strongly urge all users and organizations to update to the latest versions immediately to mitigate the risk of exploitation. The vulnerabilities impact a broad range of systems and applications that rely on OpenSSL for secure communications, making prompt patching critical for maintaining the confidentiality and integrity of data in transit. The flaws could be exploited in scenarios where attackers have access to cryptographic operations or can induce specific decryption processes. The OpenSSL advisory emphasizes that, despite the low probability of successful exploitation for some of the flaws, the potential impact warrants immediate attention. Organizations are advised to review their use of OpenSSL, especially in environments utilizing ARM platforms or custom cryptographic implementations. The updates are part of OpenSSL's ongoing commitment to maintaining the security of its cryptographic library, which underpins much of the internet's secure traffic. Security researchers continue to scrutinize OpenSSL due to its widespread deployment and critical role in protecting sensitive information. The release of these patches highlights the importance of timely vulnerability management and the need for organizations to monitor security advisories from key software suppliers. Failure to apply these updates could leave systems exposed to advanced attacks, including those that bypass traditional security controls. The OpenSSL Project's rapid response demonstrates the collaborative effort between researchers and maintainers to address security issues before they can be widely exploited.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-27, OpenSSL released version 3.6.1 to address high-severity security issues. This was the patched software release corresponding to the security advisory issued the same day.
On 2026-01-27, OpenSSL issued a new security advisory covering multiple vulnerabilities, later referenced by JVN as JVNVU#91919266. This represents a separate disclosure from the October 2025 OpenSSL fixes already in the timeline.
The disclosed flaws included an out-of-bounds read/write in CMS decryption with PWRI, a timing side-channel in SM2 signature computations on 64-bit ARM, and a low-severity denial-of-service issue. Maintainers warned that exploitation could enable key recovery, code execution, or service disruption in some scenarios, though overall attack likelihood was considered low.
On 2025-10-01, the OpenSSL Project released security updates for CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232. Patched releases included OpenSSL 3.5.4, 3.4.3, 3.3.5, 3.2.6, 3.0.18, 1.0.2zm, and 1.1.1zd.
On 2025-05-22, the OpenSSL Project published a new security advisory on its website. This is a separate OpenSSL disclosure occurring after the February 2025 CVE-2024-12797 fix and before the October 2025 vulnerability releases.
In February 2025, the OpenSSL Project released a fix for CVE-2024-12797, a high-severity vulnerability referenced as a prior security update in later coverage.
On 2025-01-20, the OpenSSL Project published a security advisory on its website. This advisory represents an earlier OpenSSL disclosure not yet reflected in the existing timeline.
12 references tracked. Mallory keeps watching after this page renders.
jvn.jp
Open sourcecyberpress.org
Open sourcelinuxiac.com
Open sourcegithub.com
Open sourcesecurityaffairs.com
Open sourceopenssl-library.org
Open sourceopenssl-library.org
Open sourceopenssl-library.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.