CVE-2026-54872 | OpenSSL up to 4.0.2 Elliptic-Curve Scalar Multiplication timing discrepancy
A vulnerability identified as problematic has been detected in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. Impacted is an unknown function of the component Elliptic-Curve Scalar Multiplication. This manipulation causes observable timing discrepancy.
This vulnerability is tracked as CVE-2026-54872. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More