CVE Tools

OpenBSD

204 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for OpenBSD, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

OpenBSD CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
OpenBSD CVEs per month
MonthCVEs
2024-100
2024-111
2024-123
2025-010
2025-020
2025-031
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-041
2026-050
2026-063
2026-070
2026-080
2026-091

Severity

How the 204 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2814%
  • High6733%
  • Medium9145%
  • Low189%

Latest CVEs

The 15 most recently published vulnerabilities affecting OpenBSD.

  1. CVE-2026-56101OpenBSD ieee80211_crypto_tkip.c TKIP MIC Countermeasure Logic Inversion DoS5.3
  2. CVE-2026-57589sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().7.4
  3. CVE-2026-56099OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input5.3
  4. CVE-2026-55706sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.5.8
  5. CVE-2026-41285In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd...4.3
  6. CVE-2026-32772telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.3.4
  7. CVE-2025-30334OpenBSD wg(4) kernel crash6.5
  8. CVE-2024-11149OpenBSD vmm GDTR limits7.9
  9. CVE-2024-10933OpenBSD readdir directory traversal5.0
  10. CVE-2024-11148OpenBSD httpd(8) null dereference7.5
  11. CVE-2024-10934OpenBSD NFS double-free vulnerability9.8
  12. CVE-2021-35000OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability3.3
  13. CVE-2021-34999OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability5.5
  14. CVE-2024-29937NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.9.8
  15. CVE-2023-52558OpenBSD 7.4 and 7.3 m_split() network buffer kernel crash7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store