Skip to content

Manually bundled OpenSSL artifacts have security advisories #32

@mbauman

Description

@mbauman

The OpenSSL artifacts that are hardcoded in Artifacts.toml have been identified as being vulnerable to multiple CVEs, including one of moderate severity (CVE-2026-31790). Now that OpenSSL_jll has been updated to 3.5.6, I'd like to update Julia's SecurityAdvisories.jl to include these advisories. That will happen upon merging JuliaLang/SecurityAdvisories.jl#346, but we try to avoid publishing advisories without an available upgrade pathway.

In general, it's much better to incorporate JLLs as direct dependencies rather than re-incorporating their artifacts — and this is precisely one reason to do so!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions