{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openssl-4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-14456"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenSSL 3.5","OpenSSL 3.6","OpenSSL 4.0"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","openssl"],"_cs_type":"advisory","_cs_vendors":["OpenSSL"],"content_html":"\u003cp\u003eThe French National Cybersecurity Agency (ANSSI) has published an advisory regarding a denial of service (DoS) vulnerability identified in the OpenSSL cryptographic library. The vulnerability, tracked as CVE-2026-14456, impacts OpenSSL versions 3.5.x (prior to 3.5.8), 3.6.x (prior to 3.6.4), and 4.0.x (prior to 4.0.2). The vulnerability allows a remote, unauthenticated attacker to cause the application to crash or become unresponsive, effectively creating a denial of service. As of the time of the advisory, the vendor had not yet released patches for the affected versions. Organizations utilizing OpenSSL for network-facing services or encrypted communications are advised to monitor the official OpenSSL security advisories for the release of updates.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a remote denial of service condition. This could lead to the unavailability of critical services that rely on OpenSSL for TLS/SSL termination, such as web servers, VPN concentrators, and application proxies. Impacted sectors include any organization relying on the OpenSSL library across varied operating systems and architectures.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor the official OpenSSL security advisory page for the release of patches for CVE-2026-14456.\u003c/li\u003e\n\u003cli\u003eAudit software inventories to identify applications or services bundling the vulnerable versions of OpenSSL (3.5.x \u0026lt; 3.5.8, 3.6.x \u0026lt; 3.6.4, 4.0.2 \u0026lt; 4.0.2).\u003c/li\u003e\n\u003cli\u003eWhere possible, implement network-level access controls to restrict traffic to critical services using OpenSSL to trusted source IP addresses until patches are applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T14:05:29Z","date_published":"2026-08-14T14:05:29Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openssl-dos/","summary":"A vulnerability (CVE-2026-14456) in OpenSSL versions 3.5.x, 3.6.x, and 4.0.x allows remote attackers to trigger a denial of service condition.","title":"Remote Denial of Service Vulnerability in OpenSSL","url":"https://feed.craftedsignal.io/briefs/2026-08-openssl-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenSSL 4.0","version":"https://jsonfeed.org/version/1.1"}