-
OpenSSL released a fix for a serious flaw in its DTLS system on September 29, 2026.
-
The bug, tracked as CVE-2026-84782, could leak private memory or crash a computer.
-
Only OpenSSL 4.0 has the bug. Older versions like 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2 stay safe.

Millions of apps and websites quietly rely on OpenSSL every single day. It runs in the background, protecting private data as it travels online. That trust just faced a serious test this week.
OpenSSL released new updates to fix a high-risk bug. The flaw sits inside DTLS, a tool that protects data sent over networks like UDP. Attackers could use this bug to steal private computer memory.
In some cases, they could crash the affected system instead. Most regular users will never notice DTLS working quietly. But the software behind the scenes still needs constant protection and care.
How the DTLS Bug Leaks Private Data
The bug carries the tracking number CVE-2026-84782. It affects how OpenSSL handles DTLS handshake messages. A handshake happens when two computers agree to talk securely. According to the OpenSSL security advisory, the problem starts when a message gets interrupted midway through sending.
DTLS works like TLS, but for data sent in small packets called datagrams. Large handshake messages often split into smaller pieces first. Sometimes, the network cannot accept more data right away. When that happens, OpenSSL pauses the message and finishes it later.
Here is where the danger begins. A timer inside DTLS tries to resend an older message during that pause. The retry can accidentally reuse the same memory space as the paused message. Instead of starting fresh, the retry reads from the wrong spot in memory.
That mistake can leak unintended data. The system might send private heap memory as if it were normal handshake data. Heap memory often holds sensitive information from other parts of a program. That could include passwords, keys, or other private program data.
In other cases, the bug works differently. It might push OpenSSL to read past its memory limit instead. That kind of error usually crashes the running program. A crash like this could shut down an entire secure connection. Attackers do not always need to steal data to cause harm. Sometimes, simply breaking a service is damaging enough for a company to suffer.
OpenSSL marked this bug as high severity. The company describes it as an out-of-bounds read error, according to the advisory.
Who Found the Bug and Which Versions Stay Safe
Security researcher Laurent Gaffie from Secorizon first reported the bug. He sent the report on August 17, 2026, according to OpenSSL’s advisory. Developer Ryan Hooper then built the fix for the issue. About six weeks passed between the report and the public patch release.
The bug lives only inside OpenSSL 4.0, in versions released before 4.0.3. Anyone running OpenSSL 4.0 should upgrade to version 4.0.3 right away, as stated by OpenSSL.
Older versions do not carry this risk. OpenSSL confirms that versions 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2 stay unaffected by this specific bug. That gives many users some peace of mind. Still, anyone unsure of their version should check it carefully now. Software teams sometimes run several OpenSSL versions across different products at once. Checking every system takes real effort, but it matters here.
More Security Fixes Land Alongside the DTLS Patch
OpenSSL released this fix as part of a larger security update on September 29, 2026. The update covers more than just the DTLS flaw. It also fixes problems tied to memory allocation and QUIC, a modern internet protocol. Windows has faced similar memory-related security issues, with three separate attacks recently targeting memory, Defender, and driver security. Other fixes touch cryptographic side channels and X.509, a format used for digital certificates.
OpenSSL’s release notes list CVE-2026-84782 alongside several other fixes inside version 3.5.9. That shows how wide this update really reaches across supported OpenSSL branches. Development teams should not assume one single patch covers everything they need.
News outlets outside OpenSSL also picked up the story quickly. The Hacker News reported on the flaw and its risk of leaking heap memory. Security sites CyberPress and GBHackers also covered the update closely. Don’t go only on our word and research; each outlet warned about the same two risks: data leaks and system crashes.
Companies and individuals who rely on OpenSSL should act soon. First, check which OpenSSL version your system currently uses. Then compare that version against the list of affected software. If you run OpenSSL 4.0 before version 4.0.3, update it immediately. Developers who build products using OpenSSL carry extra responsibility here. Their users often have no way to fix this problem themselves.
Security teams should also read the full OpenSSL advisory closely. The September update fixes more bugs than just this one high-risk flaw. Missing a smaller fix could still leave a system exposed later. Regular patching remains one of the cheapest ways to prevent bigger problems down the road.
This DTLS bug shows how small coding mistakes can create big risks. A single interrupted message caused a serious memory leak. Thankfully, OpenSSL caught the issue before major harm spread anywhere. No public reports currently describe this bug being used in real attacks. Staying updated remains the simplest way to stay protected online.