Vulnerabilities · 5h ago

OpenSSL DTLS Bug Leaks Heap Data in Handshakes

OpenSSL and WolfSSL both shipped fresh security fixes, and OpenSSL’s high-severity CVE-2026-84782 can let a remote peer recover heap fragments or crash DTLS-based software. SecurityWeek said OpenSSL patched 14 flaws in total, with one more medium-severity issue tracked as CVE-2026-84783.

The bug is in DTLS handshake retransmission. If a handshake stalls partway through sending a message, OpenSSL can resend from the wrong spot in memory and put leftover heap bytes on the wire as plaintext, so the leak happens before the session is fully established; if the read runs into unmapped memory, the service crashes. That matters anywhere OpenSSL is embedded for DTLS, including VPN, VoIP, WebRTC, and IoT products.

The exposure follows the downstream product, not just the library package. OpenSSL’s public fixes cover current branches, while older maintained lines may only be available to paying customers, so legacy deployments can sit on a different patch path than teams expect.

CVE-2026-84782

NVD KEV

CVSS 8.2 HIGH: issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended…

CVE-2026-84783

NVD KEV

CVSS 7.5 HIGH: issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached…

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-30

Editions

Related stories