Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-75803

AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
Back to all
CVE

CVE-2026-75803

AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty

ciphertext can report success without verifying the supplied authentication

tag when the operation is finalized by calling the EVP_Cipher() function.

Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and

expecting the call to check the AEAD tag may accept forged messages.

CWE: CWE-354 (Improper Validation of Integrity Check Value)

Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one

shot encryption and decryption call. It also verifies the AEAD tag after the

decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers

it skipped the AEAD tag verification when an empty ciphertext was passed to

the function. The callers of this function might believe that a successful

return indicates a valid AEAD tag for these ciphers, even when that has not

truly been validated in this case.

FIPS impact: no

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE

as the affected algorithms are not FIPS approved and thus not implemented

in the FIPS module.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75803.json, https://nvd.nist.gov/vuln/detail/CVE-2026-75803, https://openssl-library.org/news/secadv/20260825.txt, https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42, https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b, https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a, https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34, https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00221%
EPSS Percentile
0.11361%
Introduced Version
11b7b6ea3b65a584e1d31408ed1bdb139465cffd,0,3.0.0,3.4.0,3.5.0,3.6.0,4.0.0
Fix Available
bf95f5f772e9362f87b25cfa2f8cb15d984865b9,3.0.22-1~deb12u1,3.5.7-1~deb13u2,3.0.13-0ubuntu3.15,3.0.2-0ubuntu1.29,3.0.22,3.4.7,3.5.8,3.6.4,4.0.2,3.5.8-r0,3.3.7-r1,1:3.5.8-1.amzn2023.0.1,4.0.2-r0,0

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading