Skip to content

Libcrypto in OpenSSL Version 3.3.3 affected by multiple CVEs #9078

Description

@LevN0

Nessus is complaining that the bundled libcrypto is affected by CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789 and CVE-2026-31790; all these were disclosed in this advisery.

Tenable Nessus Agent reports the following:

"
Path : /usr/local/aws-sam-cli/1.161.1/dist/_internal/libcrypto.so.3
Reported version : 3.3.3
Fixed version : 3.3.7
"

Could we please bump OpenSSL to 3.3.7, or otherwise declare this non-exploitable (if so)?

Metadata

Metadata

Assignees

No one assigned

    Labels

    stage/waiting-for-releaseFix has been merged to develop and is waiting for a release

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions