CVE-2026-54875 | OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2 SM2 timing discrepancy

SecurityVulns

A vulnerability described as problematic has been identified in OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2. This affects an unknown function of the component SM2. Executing a manipulation can lead to observable timing discrepancy.

This vulnerability is registered as CVE-2026-54875. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More