
🛡️ Multiple OpenSSL vulnerabilities expose sensitive data in RSA KEM Handling Source: https://cybersecuritynews.com/openssl-vulnerabilities-expose-data/ OpenSSL has released a broad April 2026 security update that fixes seven vulnerabilities across supported branches, led by CVE-2026-31790, a moderate-severity flaw in RSA KEM RSASVE encapsulation that can expose uninitialized memory to a malicious peer. The advisory directs users of vulnerable 3.x releases to move to OpenSSL 3.0.20, 3.3.7, 3.4.5, 3.5.6, or 3.6.2, depending on the branch in use. The most serious issue, CVE-2026-31790, affects applications that use EVP_PKEY_encapsulate() with RSA/RSASVE to derive a shared secret from an attacker-supplied RSA public key without validating that key first. #cybersecuritynews
Post summary
The advisory announces an OpenSSL update addressing seven CVEs, notably CVE-2026-31790, providing specific version fixes and technical details about the vulnerability.
















