Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-84782
CVE
CVE-2026-84782
View on NVD ↗
DTLS Retransmits Handshake Messages From a Stale Buffer Offset
Source Articles
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
OpenSSL has addressed a high-severity vulnerability, CVE-2026-84782, affecting DTLS implementations that can lead to heap memory leakage in unencrypted handshake data or cause a program crash. The flaw occurs when a DTLS handshake message is resent while a larger message is partially sent, resulting in the use of incorrect buffer positioning and potential exposure of sensitive memory contents. The vulnerability impacts multiple OpenSSL branches, with public fixes available for newer versions and only premium support customers receiving updates for older versions like 3.0, 1.1.1, and 1.0.2.
hacker-news
Sep 30, 2026