https://seclists.org/oss-sec/2026/q3/489: OpenSSL Security Advisory
Published Aug 13, 2026
·Updated
Affected Software
3 affected components
OpenSSL OpenSSL>3.4<=3.4
OpenSSL OpenSSL 4.0=4.0
OpenSSL OpenSSL 3.6=3.6
The severity of CVE-2026-14456 is classified as low.
CVE-2026-14456 affects the QUIC server incoming channel queue in OpenSSL.
To fix CVE-2026-14456, users should update to the latest version of OpenSSL that addresses this vulnerability.
CVE-2026-14456 impacts OpenSSL 3.6 and OpenSSL 4.0.
CVE-2026-14456 describes unbounded memory growth in the QUIC server's incoming channel queue.