OpenBSD
204 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for OpenBSD, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
OpenBSD CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 3 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 3 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 204 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical28
- High67
- Medium91
- Low18
Latest CVEs
The 15 most recently published vulnerabilities affecting OpenBSD.
- CVE-2026-56101OpenBSD ieee80211_crypto_tkip.c TKIP MIC Countermeasure Logic Inversion DoS5.3
- CVE-2026-57589sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().7.4
- CVE-2026-56099OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input5.3
- CVE-2026-55706sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.5.8
- CVE-2026-41285In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd...4.3
- CVE-2026-32772telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.3.4
- CVE-2025-30334OpenBSD wg(4) kernel crash6.5
- CVE-2024-11149OpenBSD vmm GDTR limits7.9
- CVE-2024-10933OpenBSD readdir directory traversal5.0
- CVE-2024-11148OpenBSD httpd(8) null dereference7.5
- CVE-2024-10934OpenBSD NFS double-free vulnerability9.8
- CVE-2021-35000OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability3.3
- CVE-2021-34999OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability5.5
- CVE-2024-29937NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.9.8
- CVE-2023-52558OpenBSD 7.4 and 7.3 m_split() network buffer kernel crash7.5
Product grouping is registry-driven, with AI assist and human review. How it works