OpenSSL 4.0.3 was released today as a security patch for the widely used open-source cryptography and TLS toolkit. It addresses a sizeable batch of vulnerabilities across DTLS, QUIC, X.509 processing, elliptic-curve operations, and other components.
According to the OpenSSL team, the most severe vulnerability fixed in this release has a High severity rating. In total, OpenSSL 4.0.3 includes fixes or mitigations for 14 CVEs.
Among them is CVE-2026-84782, which affects DTLS handshake retransmissions, along with CVE-2026-84783, a use-after-free issue in the X.509 extension cache that can occur under concurrent use.
Several QUIC-related vulnerabilities are also addressed, including excessive amplification credit accounting, a potential CPU denial-of-service caused by inefficient fragment reassembly, a STREAM fragment metadata DoS, missing connection-level flow-control enforcement, and an unbounded RETIRE_CONNECTION_ID backlog.
The update also fixes excessive memory allocation during CRL distribution point processing. It also resolves an out-of-bounds access issue involving SSL_set_SSL_CTX() during a handshake, a NULL pointer dereference in CMP client revocation response handling, and a DTLS 1.2 denial-of-service condition triggered by an undersized unauthenticated AEAD record.
Cryptographic operations also receive attention. OpenSSL 4.0.3 resolves timing side-channel issues affecting scalar multiplication on non-NIST elliptic curves and SM2 signature generation, as well as non-constant-time SM2 scalar multiplication on ARM64 and RISC-V systems.
Beyond the security fixes, the release corrects a bug where EVP_DecryptFinal() could incorrectly report stale success after an AES-SIV authentication failure. It also fixes a regression in OpenSSL 4.0’s base64 encoding BIO filter that could cause encoded data loss after incomplete writes down the BIO chain.
Given the number and scope of the security fixes, users and administrators running OpenSSL 4.0 are advised to update to version 4.0.3 as packages become available through their operating system or software distribution channels.
For additional details, see the changelog.
