close
Skip to content

[GHSA-wj64-gh9j-xm82] Issue summary: An OpenSSL TLS 1.3 server may fail to...#7312

Open
vdukhovni wants to merge 1 commit intovdukhovni/advisory-improvement-7312from
vdukhovni-GHSA-wj64-gh9j-xm82
Open

[GHSA-wj64-gh9j-xm82] Issue summary: An OpenSSL TLS 1.3 server may fail to...#7312
vdukhovni wants to merge 1 commit intovdukhovni/advisory-improvement-7312from
vdukhovni-GHSA-wj64-gh9j-xm82

Conversation

@vdukhovni
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • Description
  • Severity
  • Summary

Comments
It makes no sense to give this CVE a HIGH rating. I barely convinced the OpenSSL security response team to assign a CVE at all. This is a deviation from documented behaviour, but there's no attack vector, other than perhaps record all the traffic, and perhaps someday decrypt, but only relevant under the multiple uncommon conditions that result in the deviation from documented behaviour.

@github-actions github-actions bot changed the base branch from main to vdukhovni/advisory-improvement-7312 April 7, 2026 05:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant