https://seclists.org/oss-sec/2026/q3/489: OpenSSL Security Advisory
Published Aug 13, 2026
·Updated
Affected Software
3 affected components
OpenSSL OpenSSL>3.4<=3.4
OpenSSL OpenSSL 4.0=4.0
OpenSSL OpenSSL 3.6=3.6
Frequently Asked Questions
1
What is the severity of CVE-2026-14456?
The severity of CVE-2026-14456 is classified as low.
2
What does CVE-2026-14456 affect?
CVE-2026-14456 affects the QUIC server incoming channel queue in OpenSSL.
3
How do I fix CVE-2026-14456?
To fix CVE-2026-14456, users should update to the latest version of OpenSSL that addresses this vulnerability.
4
What versions of OpenSSL are affected by CVE-2026-14456?
CVE-2026-14456 impacts OpenSSL 3.6 and OpenSSL 4.0.
5
What is the nature of the issue described in CVE-2026-14456?
CVE-2026-14456 describes unbounded memory growth in the QUIC server's incoming channel queue.