OpenSSL has disclosed a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation. The flaw could let a remote peer read unintended plaintext heap memory during handshake data transmission, or cause a denial-of-service condition. Tracked as CVE-2026-84782, it stems from an out-of-bounds read in how DTLS handshake message retransmissions are handled.
According to the Security Advisory published on September 29, 2026, the bug affects OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2.
How CVE-2026-84782 Breaks OpenSSL’s DTLS Retransmission Logic
DTLS is built for datagram-based transports, where packets can go missing, so it includes retransmission mechanisms to recover lost handshake packets. That recovery feature is where the problem lies.
The trouble starts when an application sends a DTLS handshake message in several fragments and the transport temporarily stops accepting data. OpenSSL may then return a WANT_WRITE status, pausing the handshake write partway through. While the write is suspended, a DTLS retransmission timer can expire and try to resend an earlier handshake message from the retransmission queue.
At that point, OpenSSL’s retransmission code wrongly reuses the internal buffer and tracking state tied to the paused write. Instead of resetting its read position to the start of the queued message, it may begin at the offset the in-progress write had already reached.
As a result, a peer can receive a malformed or mislabeled DTLS handshake message containing leftover bytes from an unrelated, larger message still in transit. In some cases, the read extends past the intended buffer, exposing heap-resident data in plaintext.
Memory Disclosure and Crash Risks
The weakness is classified as CWE-125, an out-of-bounds read, and its main security impact is unintended disclosure of heap memory to the remote DTLS peer. What leaks depends on the process’s memory contents and runtime conditions, and it could include fragments of previously allocated application or library data. The advisory, however, has not confirmed any reliable arbitrary-memory disclosure capability.
The bug can also crash a process if the retransmission logic reads from an unmapped memory region, creating a denial-of-service risk for applications that handle attacker-controlled DTLS traffic.
A related issue in the same retransmission path can corrupt the bookkeeping needed to resume the suspended handshake write. If a retransmission occurs while another write is still paused, later calls to SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() may run into inconsistent states, triggering an abort in debugging builds.
OpenSSL Releases Fixes for the DTLS Vulnerability
OpenSSL fixed the problem by resetting the retransmission read position before a message is resent. The patch also skips retransmissions while a handshake write is suspended, deferring them until the application resumes the pending operation.
| Affected branch | Fixed release |
| OpenSSL 4.0 | 4.0.3 |
| OpenSSL 3.6 | 3.6.5 |
| OpenSSL 3.5 | 3.5.9 |
| OpenSSL 3.4 | 3.4.8 |
| OpenSSL 3.0 Premium Support | 3.0.23 |
| OpenSSL 1.1.1 Premium Support | 1.1.1zj |
| OpenSSL 1.0.2 Premium Support | 1.0.2zs |
The OpenSSL FIPS module is not affected, since the vulnerable DTLS code sits outside its boundary.
Organizations are advised to identify internet-facing services, VPNs, VoIP systems, IoT deployments, and custom applications that rely on DTLS, and to promptly upgrade their bundled or system-provided OpenSSL packages.
Laurent Gaffie of SecuRizon reported CVE-2026-84782 on August 17, 2026, and Ryan Hooper developed the fix.






































