CVE-2026-31790Patch(openssl / openssl)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openssl openssl systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext. As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue. The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.

2.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 20 mentions across 8 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 14 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 11 mentions (2026-04-08); latest day: 1
  • 20 total mentions across 8 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline20 mentions / 8d
036811Mentions · 2026-04-07: 3Mentions · 2026-04-08: 11Mentions · 2026-04-09: 1Mentions · 2026-04-11: 1Mentions · 2026-04-12: 1Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-04-28: 1Exploit Tool / Code · 2026-04-11: 1Patch / Workaround · 2026-04-07: 3Patch / Workaround · 2026-04-08: 8Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 9Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-15: 104-0704-0804-0904-1104-1204-1404-1504-28
Signal classification3 categories
Patch
945.0%
Disclosure
840.0%
General
315.0%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-073
Disclosure1Patch2
2026-04-0811
Disclosure4Patch7
2026-04-091
General1
2026-04-111
General1
2026-04-121
General1
2026-04-141
Disclosure1
2026-04-151
Disclosure1
2026-04-281
Disclosure1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Patch

    🛡️ Multiple OpenSSL vulnerabilities expose sensitive data in RSA KEM Handling Source: https://cybersecuritynews.com/openssl-vulnerabilities-expose-data/ OpenSSL has released a broad April 2026 security update that fixes seven vulnerabilities across supported branches, led by CVE-2026-31790, a moderate-severity flaw in RSA KEM RSASVE encapsulation that can expose uninitialized memory to a malicious peer. The advisory directs users of vulnerable 3.x releases to move to OpenSSL 3.0.20, 3.3.7, 3.4.5, 3.5.6, or 3.6.2, depending on the branch in use. The most serious issue, CVE-2026-31790, affects applications that use EVP_PKEY_encapsulate() with RSA/RSASVE to derive a shared secret from an attacker-supplied RSA public key without validating that key first. #cybersecuritynews

    Post summary

    The advisory announces an OpenSSL update addressing seven CVEs, notably CVE-2026-31790, providing specific version fixes and technical details about the vulnerability.

    228096244.6K
    65.9K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    OpenSSL Security Advisory [7th April 2026] https://www.openwall.com/lists/oss-security/2026/04/07/11 7 CVEs fixed, 1 of them Moderate: CVE-2026-31790: Incorrect Failure Handling in RSA KEM RSASVE Encapsulation The remaining 6 are Low

    Post summary

    The advisory announces the patching of seven CVEs, including CVE-2026-31790, which is classified as moderate severity.

    01072637
    4.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    OpenSSL の脆弱性 CVE-2026-31790 が FIX:RSA KEM 操作における機密情報の漏洩 https://iototsecnews.jp/2026/04/08/multiple-openssl-vulnerabilities-exposes-sensitive-data-in-rsa-kem-handling/ 今回のセキュリティ・アップデートにおいて、OpenSSL 3.x 系列のコード内で関数の戻り値を確認する際のロジック不備に起因する、脆弱性 CVE-2026-31790 が修正されました。具体的には、RSA 暗号化を行う関数が失敗した際に返す “-1” という値を、正しくエラーとして処理せず、成功と誤認して処理を継続するバグが生じています。その結果として、暗号化が失敗した場合において、バッファ内に残っていた未初期化のデータや過去の機密情報などが、そのまま相手に送信されてしまう恐れがあります。ご利用のチームは、ご注意ください。 #CVE202631790 #OpenSSL #Vulnerability

    Post summary

    Japanese news reports that CVE-2026-31790 in OpenSSL 3.x has been fixed, explains the bug that allowed sensitive data leakage due to incorrect error handling, and notes the patch but offers no PoC, exploit, or active exploitation details.

    01001145
    484 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl モジュール更新情報 3.5.6-1 https://kusanagi.tokyo/releases/24085/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 openssl 3.5.6-1 この更新には脆弱性(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-317...

    Post summary

    The posted update provides a patched OpenSSL version (3.5.6-1) that addresses several CVEs, serving as a vendor patch announcement.

    01010104
    200 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    OpenSSL's April 2026 advisory reveals 7 flaws, including a moderate RSA memory leak (CVE-2026-31790). Learn if your version is affected and how to patch. #OpenSSL #CyberSecurity #InfoSec #RSALeak #PatchTuesday #VulnerabilityUpdate #LinuxSecurity https://securityonline.info/openssl-security-advisory-april-2026-rsa-memory-leak/ https://t.co/NApyU1ZHJ7

    Post summary

    OpenSSL released an April 2026 advisory outlining seven flaws, including CVE‑2026‑31790, a moderate RSA memory leak. The advisory provides patch guidance and urges affected users to update.

    00020270
    12.3K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    OpenSSLの脆弱性(Moderate: CVE-2026-31790, Low: CVE-2026-28386〜CVE-2026-28390, CVE-2026-31789)と3.6.2, 3.5.6, 3.4.5, 3.3.7, 3.0.20, 1.1.1zg, 1.0.2zpリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssl #openssl https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260408/

    Post summary

    The message discloses several moderate and low‑severity OpenSSL CVEs and references new releases of the library that address these vulnerabilities.

    00020185
    370 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Oracle ❗ CVE-2026-35229 ❗ CVE-2026-33870 ❗ CVE-2026-31790 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-oracle-2/ https://t.co/y1CAnFesIT

    Post summary

    The tweet announces the identification of three new Oracle CVEs, directing readers to an external link for more information, but it does not provide details on exploitation, patches, or technical specifics.

    00001135
    6.7K followersView on X
  • Mr. OS@ksg93rd
    General

    #Analytics #Threat_Research An analytical review of the main cybersecurity events for the week (Apr.4-11, 2026) 1⃣. OpenSSL maintenance releases https://github.com/openssl/openssl/tags // OpenSSL 3.6.2, 3.5.6, 3.4.5, 3.3.7, which fix 7 vulnerabilities, incl. CVE-2026-31790 https://github.com/advisories/GHSA-vgxx-5xj5-q97x 2⃣. GlassWorm goes native: New Zig dropper infects every IDE on your machine https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine // Extension impersonates WakaTime, popular developer time-tracking tool, and ships a Zig-compiled native binary alongside its JavaScript code 3⃣. Claude Mythos - new LLM from Anthropic https://www.anthropic.com/glasswing // Assessing Claude Mythos cybersecurity capabilities https://red.anthropic.com/2026/mythos-preview/ 4⃣. Node.js Trust Falls: https://www.zerodayinitiative.com/blog/2026/4/8/nodejs-trust-falls-dangerous-module-resolution-on-windows Dangerous Module Resolution on Windows // Node.js on Windows defaults to insecure module resolution in C:\node_modules, enabling privilege escalation, with major vendors dismissing the security risk despite longstanding awareness since 2013... 5⃣. High-tech vulnerability in PDF files https://justhaifei1.blogspot.com/2026/04/expmon-detected-sophisticated-zero-day-adobe-reader.html // Such a mechanism allows the threat actor to collect user information, steal local data, perform advanced fingerprinting, and launch future attacks: if the target meets the attacker's conditions, the attacker may deliver additional exploit to achieve RCE/SBX 6⃣. Apache Solr Path Traversal RCE Attack https://blog.securelayer7.net/cve-2024-52012-apache-solr-zip-slip-rce-attack/ // CVE-2024-52012 is a Zip Slip vulnerability in Apache Solr’s ConfigSet Upload API allowing unauthenticated RCE via crafted ZIP files with path traversal sequences 7⃣. Microsoft Speech https://ipurple.team/2026/04/07/microsoft-speech/ // SpeechRuntime.exe can be exploited for lateral movement through COM hijacking and session enumeration

    Post summary

    The post is a weekly roundup of various CVEs, noting OpenSSL patches and detailing several vulnerabilities (Node.js, Apache Solr, PDF, Microsoft Speech) but provides no PoC or active exploitation claims.

    00001173
    3.3K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-31790 impacts openssl-fips-provider-latest in 20 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/472 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE (CVE‑2026‑31790) affecting the openssl‑fips‑provider‑latest component in AWS Lambda base images has been identified, with details linked to a GitHub issue.

    0000031
    34 followersView on X
  • ますだまさる@m_masaru
    General

    SSLの観点で見ていくと https://nvd.nist.gov/vuln/detail/CVE-2026-28386 CVE-2026-31790 RSA KEMはSSLで使用しないので影響なし CVE-2026-28386 CFBモードはSSLで使用しないので影響なし CVE-2026-28387 DONEはDNSSECベースの証明書検証の仕組みだけどSSL実装レイヤで対応はないので影響なし CVE-2026-28388 delta CRLは、ブラウザは独自にCRLをチェックしているしブラウザ以外は基本CRLをチェックしていないのでSSLに影響なし。SSLでのVPNとかに限定するとあるかも CVE-2026-28389 CMSはSSLで使用していないので影響なし CVE-2026-28390 CMSは同上 CVE-2026-31789 32bit環境で1GiBを超えるOCTET STRINGを含んだ証明書をロードすると発生するのだけど、SSL handshakeのserver cerfificatesのlengthが24bitでmax 16MiBなのでSSLには影響なし

    Post summary

    The post enumerates several CVEs, noting each has no impact on SSL usage, and provides brief technical context but no actionable exploitation or mitigation information.

    00000188
    149 followersView on X
  • K.Namba/(お菓子|おやつ)エバンジェリストDX🍩@ipv6labs
    General

    OpenSSH 上げた。 CVE-2026-31790 は LibreSSL には影響しない模様 $ /usr/local/openssh/bin/ssh -V OpenSSH_10.3p1, LibreSSL 4.2.1

    Post summary

    The post notes that CVE-2026-31790 does not affect LibreSSL in an OpenSSH 10.3p1 environment, but offers no further technical or exploit details.

    00000175
    2.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    OpenSSL releases patch fixing seven vulnerabilities including CVE-2026-31790, a data leakage flaw from uninitialized memory in RSA key encapsulation. Affects versions 3.0 to 3.6. #OpenSSLUpdate #DataLeakage #CVE2026 https://ift.tt/LjGsgtX

    Post summary

    OpenSSL released a patch fixing seven vulnerabilities, including CVE-2026-31790, a data‑leakage flaw tied to uninitialized memory in RSA key encapsulation affecting versions 3.0 to 3.6.

    00000147
    3.9K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Critical OpenSSL Flaw Exposes Sensitive Data: #CVE-2026-31790 RSA KEM Vulnerability - #Update Now! + Video https://undercodetesting.com/critical-openssl-flaw-exposes-sensitive-data-cve-2026-31790-rsa-kem-vulnerability-update-now-video/ Educational Purposes!

    Post summary

    The tweet announces the discovery of a critical RSA KEM vulnerability in OpenSSL (CVE‑2026‑31790) and urges users to update, but it offers no PoC, exploit code, or patch details.

    0000060
    464 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** OpenSSL RSA KEM (RSASVE) Memory Disclosure (CVE-2026-31790) 📅 **Timeline:** Disclosure: 2026-04-07; Patch: Not Available 🆔 **CVE-2026-31790** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** OpenSSL FIPS modules 3.0–3.6 🫨 **Attack Vectors:** - Remote malicious peer using an attacker-supplied invalid RSA public key during RSASVE/EVP_PKEY_encapsulate to trigger disclosure of uninitialized application memory 📝 **Summary:** A remote peer can supply an invalid RSA public key during RSASVE encapsulation to cause EVP_PKEY_encapsulate to return uninitialized ciphertext, potentially leaking process memory. This may expose secret material (including keys) in applications using affected OpenSSL FIPS modules. 📈 **Impact Scope:** Disclosure of uninitialized process memory may expose secret material (including keys) and other sensitive data to a remote attacker; affects applications performing RSASVE encapsulation with the listed FIPS modules. 🛡️ **Recommended Actions:** - Apply vendor patches when published and monitor the OpenSSL advisory. - As an immediate mitigation, call EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate(). - Validate RSA public keys before use. - Rotate keys/secrets if exposure is suspected and update FIPS modules promptly. 🪢 **Related Resources:** - https://openssl-library.org/news/secadv/20260407.txt - https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac 🏷 **Tags:** #Cybersecurity #OpenSSL #FIPS

    Post summary

    The advisory announces CVE‑2026‑31790, a memory disclosure in OpenSSL’s RSASVE/EVP_PKEY_encapsulate that can leak process memory via an attacker‑supplied invalid RSA key. No patch is yet available; mitigations include key validation and monitoring until a fix is released.

    0000010
    276 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** OpenSSL RSA KEM (RSASVE) Uninitialized Memory Exposure (CVE-2026-31790) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: 2026-04-07 🆔 **CVE-2026-31790** | 📊 CVSS: (Medium 🟡) 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** FIPS modules: 3.6, 3.5, 3.4, 3.3, 3.1 (includes 3.0) 🔧 **Fixed Versions:** OpenSSL April 2026 security update 🫨 **Attack Vectors:** - Malicious peer supplying an invalid RSA public key during RSASVE/EVP_PKEY_encapsulate() (remote interaction) - Use of EVP_PKEY_encapsulate() without prior public-key validation 📝 **Summary:** An RSASVE encapsulation bug can report success despite failed RSA encryption, allowing EVP_PKEY_encapsulate() to return uninitialized/stale ciphertext that a remote peer could read. This may disclose sensitive process memory (including secrets) to attackers interacting via RSASVE. 📈 **Impact Scope:** Potential disclosure of uninitialized/stale process memory (sensitive data, secrets) to a remote attacker interacting via RSASVE; affects listed OpenSSL FIPS modules. 🛡️ **Recommended Actions:** - Apply the OpenSSL April 2026 security update immediately - If you cannot update immediately, call EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() as a mitigation - Audit uses of RSASVE/EVP_PKEY_encapsulate() and ensure public keys are validated prior to encapsulation - Replace/rotate keys or secrets if exposure is suspected 🪢 **Related Resources:** - https://openssl-library.org/news/secadv/20260407.txt - https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac 🏷 **Tags:** #Cybersecurity #OpenSSL #RSASVE

    Post summary

    The advisory announces CVE‑2026‑31790, details its technical impact, and emphasizes applying the April 2026 OpenSSL security update or performing manual mitigations.

    0000027
    276 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl Module Update 3.5.6-1 https://kusanagi.tokyo/en/releases/24086/ KUSANAGI 9 modules have been updated. The updated modules are as follows: openssl 3.5.6-1 This update includes support for vulnerability(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388,...

    Post summary

    The Kusanagi openSSL module release 3.5.6‑1 updates the KUSANAGI 9 modules to address multiple OpenSSL CVEs, indicating a patch update.

    0000091
    200 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in OpenSSL 3.6.x (eight CVEs: RSA KEM, AES-CFB-128, DANE, CMS, delta CRL, hex conversion) 📅 **Timeline:** Disclosure: 2026-03-13, Patch: 2026-04-07 🆔 **CVE-2026-31790** 🆔 **CVE-2026-2673** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 13.657% 🆔 **CVE-2026-28386** 🆔 **CVE-2026-28387** 🆔 **CVE-2026-28388** 🆔 **CVE-2026-28389** 🆔 **CVE-2026-28390** 🆔 **CVE-2026-31789** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** OpenSSL 3.6.x, OpenSSL 3.5.x 🔧 **Fixed Versions:** OpenSSL 3.6.2, OpenSSL 3.5.6 🫨 **Attack Vectors:** - Network-facing TLS/KEM operations (RSASVE) - AES-CFB-128 processing on x86-64 with AVX-512 - DANE TLSA-based client processing - Processing of attacker-controlled CRLs (delta CRL) - Processing of attacker-controlled CMS EnvelopedData (KeyAgree and KeyTransport) - Conversion/printing of large X.509 extension OCTET STRINGS (32-bit platforms) 📝 **Summary:** Multiple memory-safety and parsing bugs in OpenSSL 3.6.x (and some 3.5.x) can cause crashes (DoS), memory disclosure (notably RSA KEM and AES-CFB-128 on AVX‑512), and in constrained cases heap overflow leading to potential code execution on 32‑bit. Prioritize patching systems that perform TLS/KEM operations, process CMS/CRLs/TLSA records, or run on x86‑64 with AVX‑512. 📈 **Impact Scope:** Library-level issues in OpenSSL 3.6.x (and some 3.5.x) enabling crashes (DoS), memory disclosure (RSA KEM, AES-CFB read), and potential memory corruption or code execution (heap overflow on 32-bit); affects servers and clients that use the vulnerable APIs or process untrusted CMS/CRL/certificates. Prioritize AES-CFB-128 on x86-64 with AVX-512 due to memory-read exposure. 🛡️ **Recommended Actions:** - Upgrade affected deployments to OpenSSL 3.6.2 (or OpenSSL 3.5.6 for 3.5 users) and redeploy dependent software immediately. - Apply vendor patches and rebuild/redeploy static-linked/OpenSSL-linked binaries. - For RSASVE (CVE-2026-31790), validate RSA public keys before encapsulation (EVP_PKEY_public_check() / EVP_PKEY_public_check_quick()); avoid processing untrusted CMS/CRL/TLSA inputs where possible. 🪢 **Related Resources:** - https://github.com/openssl/openssl/releases/tag/openssl-3.6.2 - https://openssl-library.org/news/secadv/20260407.txt 🏷 **Tags:** #Cybersecurity #OpenSSL #Crypto

    Post summary

    The post announces multiple OpenSSL 3.6.x vulnerability details, lists affected versions, and recommends patching to 3.6.2 (or 3.5.6), providing actionable remediation steps.

    0000041
    276 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31790 Information Disclosure in OpenSSL RSASVE Key Encapsulation via Uninitialized Memory Buffer https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31790

    Post summary

    CVE-2026-31790 is an information‑disclosure vulnerability in OpenSSL’s RSASVE key‑encapsulation implementation caused by an uninitialized memory buffer, with no PoC or exploit details referenced.

    0000074
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious pee… https://www.cve.org/CVERecord?id=CVE-2026-31790

    Post summary

    CVE-2026-31790 is an announced memory disclosure vulnerability where applications using RSASVE key encapsulation can leak uninitialized memory contents to a malicious peer.

    00000153
    57.0K followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.2 Is Now Available for Download with Important Security Fixes Patches CVE-2026-31790, CVE-2026-2673, CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, and CVE-2026-31789. https://9to5linux.com/openssl-3-6-2-is-now-available-for-download-with-important-security-fixes

    Post summary

    The article announces the release of OpenSSL 3.6.2, highlighting that it includes patches for multiple CVEs (CVE‑2026‑31790, CVE‑2026‑2673, CVE‑2026‑28386‑28390, CVE‑2026‑31789).

    0000064
    139 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more