Nessus is complaining that the bundled libcrypto is affected by CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789 and CVE-2026-31790; all these were disclosed in this advisery.
Tenable Nessus Agent reports the following:
"
Path : /usr/local/aws-sam-cli/1.161.1/dist/_internal/libcrypto.so.3
Reported version : 3.3.3
Fixed version : 3.3.7
"
Could we please bump OpenSSL to 3.3.7, or otherwise declare this non-exploitable (if so)?
Nessus is complaining that the bundled libcrypto is affected by CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789 and CVE-2026-31790; all these were disclosed in this advisery.
Tenable Nessus Agent reports the following:
"
Path : /usr/local/aws-sam-cli/1.161.1/dist/_internal/libcrypto.so.3
Reported version : 3.3.3
Fixed version : 3.3.7
"
Could we please bump OpenSSL to 3.3.7, or otherwise declare this non-exploitable (if so)?