[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-MGASA-2026-0253":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":44,"duplicates":45,"related":46,"reserved_at":9,"published_at":47,"modified_at":48,"state":9,"summary":49,"references_raw":51,"kevs":88,"epss":9,"epss_history":89,"metrics":90,"affected":91},"MGASA-2026-0253","Updated openssl packages fix security vulnerabilities\n\nThe updated packages fix security vulnerabilities:\nPossible Heap Buffer Overflow in ASN.1 Multibyte String Conversion.\n(CVE-2026-7383)\nOut-of-Bounds Read in CMS Password-Based Decryption. (CVE-2026-9076)\nHeap Buffer Over-read in ASN.1 Content Parsing. (CVE-2026-34180)\nPKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys.\n(CVE-2026-34181)\nCMS AuthEnvelopedData Processing May Accept Forged Messages.\n(CVE-2026-34182)\nUnbounded Memory Growth in the QUIC PATH_CHALLENGE Handler.\n(CVE-2026-34183)\nNULL Pointer Dereference in QUIC Server Initial Packet Handling.\n(CVE-2026-42764)\nPossible NULL Dereference in Password-Based CMS Decryption.\n(CVE-2026-42766)\nNULL Pointer Dereference in CRMF EncryptedValue Decryption.\n(CVE-2026-42767)\nMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and\nPKCS7_decrypt(). (CVE-2026-42768)\nTrust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate.\n(CVE-2026-42769)\nFFC-DH Peer Validation Uses Attacker-Supplied q. (CVE-2026-42770)\nAES-OCB IV Ignored on EVP_Cipher() Path. (CVE-2026-45445)\nIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV\nmodes. (CVE-2026-45446)\nHeap Use-After-Free in the PKCS7_verify(). (CVE-2026-45447)\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42],{"_key":15},"CVE-2026-34180",{"_key":17},"CVE-2026-34181",{"_key":19},"CVE-2026-34182",{"_key":21},"CVE-2026-34183",{"_key":23},"CVE-2026-42764",{"_key":25},"CVE-2026-42766",{"_key":27},"CVE-2026-42767",{"_key":29},"CVE-2026-42768",{"_key":31},"CVE-2026-42769",{"_key":33},"CVE-2026-42770",{"_key":35},"CVE-2026-45445",{"_key":37},"CVE-2026-45446",{"_key":39},"CVE-2026-45447",{"_key":41},"CVE-2026-7383",{"_key":43},"CVE-2026-9076",[],[],[],"2026-07-15T17:33:12Z","2026-07-15T17:49:59.909323566Z",{"cisa_kev":50,"cisa_ransomware":50,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[52,58,63,68,72,76,80,84],{"url":53,"sources":54,"tags":56},"https://advisories.mageia.org/MGASA-2026-0253.html",[55],"osv_mageia",[57],"Advisory",{"url":59,"sources":60,"tags":61},"https://bugs.mageia.org/show_bug.cgi?id=35662",[55],[62],"REPORT",{"url":64,"sources":65,"tags":66},"https://www.openwall.com/lists/oss-security/2026/06/09/15",[55],[67],"WEB",{"url":69,"sources":70,"tags":71},"https://ubuntu.com/security/notices/USN-8414-1",[55],[57],{"url":73,"sources":74,"tags":75},"https://lists.debian.org/debian-security-announce/2026/msg00245.html",[55],[67],{"url":77,"sources":78,"tags":79},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M6FSVWKLYXUHNRSEKJHJA6OVPW64N45U/",[55],[67],{"url":81,"sources":82,"tags":83},"https://openssl-library.org/news/secadv/20260609.txt",[55],[67],{"url":85,"sources":86,"tags":87},"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YTQ27HDP33LD6AS24REY2JEVD6LKVTQQ/",[55],[67],[],[],[],[92,104],{"ecosystem":93,"name":94,"vendor":95,"product":94,"cpe_part":9,"purl_type":96,"purl_namespace":95,"purl_name":94,"source":9,"versions":97},"Mageia","openssl","mageia","rpm",[98],{"version":99,"is_range":100,"range_type":101,"version_start":9,"version_start_type":9,"version_end":102,"version_end_type":103,"fixed_in":9},"lt3_5_7_1_mga10",true,"ecosystem","3.5.7-1.mga10","excluding",{"ecosystem":93,"name":94,"vendor":95,"product":94,"cpe_part":9,"purl_type":96,"purl_namespace":95,"purl_name":94,"source":9,"versions":105},[106],{"version":107,"is_range":100,"range_type":101,"version_start":9,"version_start_type":9,"version_end":108,"version_end_type":103,"fixed_in":9},"lt3_0_21_1_mga9","3.0.21-1.mga9"]