CVE-2026-77696 | OpenSSL up to 4.0.2 SM2 Signature Generation timing discrepancy
A vulnerability labeled as problematic has been found in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. The affected element is an unknown function of the component SM2 Signature Generation. Such manipulation leads to observable timing discrepancy.
This vulnerability is listed as CVE-2026-77696. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More