OpenSSL has published a security update covering multiple vulnerabilities across its supported branches, including issues involving certificate processing and QUIC.
One of the broadly relevant flaws is CVE-2026-35189, which can cause disproportionate memory allocation when OpenSSL processes certificates containing many relative CRL distribution points.
What CVE-2026-35189 does
OpenSSL says a crafted certificate or certificate set small enough to fit within normal peer-certificate limits can trigger several hundred megabytes of resident-memory allocation during a TLS handshake. With enough concurrent connections, that memory pressure could cause a client or server to fail.
The issue affects OpenSSL 4.0, 3.6, 3.5, 3.4 and supported premium-maintenance branches including 3.0, 1.1.1 and 1.0.2.
Which versions contain the fix?
- OpenSSL 4.0 users: upgrade to 4.0.3.
- OpenSSL 3.6 users: upgrade to 3.6.5.
- OpenSSL 3.5 users: upgrade to 3.5.9.
- OpenSSL 3.4 users: upgrade to 3.4.8.
- Premium-support OpenSSL 3.0 users: upgrade to 3.0.23.
Premium-support fixes also exist for older 1.1.1 and 1.0.2 branches.
QUIC issues are more version-specific
The advisory also includes QUIC vulnerabilities, including CVE-2026-35191. Not every issue affects every OpenSSL branch, so administrators should match their deployed version against the official advisory rather than applying a generic assumption.
How to respond
First identify which OpenSSL library your application or operating system is actually using. Many Linux distributions backport security fixes, so the package version supplied by a distribution may differ from upstream numbering.
Server operators should use vendor packages where appropriate, test updates in staging, restart services that have loaded the old library and confirm the running processes are using the patched build.
Bottom line
The September update includes multiple issues, but the practical response is straightforward: inventory OpenSSL versions, consult the branch-specific advisory and apply the fixed package supplied by OpenSSL or your operating-system vendor.