CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2025-66199: OpenSSL TLS 1.3 Certificate Compression Heap Buffer Overflow

July 17, 2026

A low-severity vulnerability in OpenSSL's TLS 1.3 certificate compression feature allows a peer-supplied length to grow a heap buffer before validation, potentially leading to memory exhaustion of up to 22 MiB per connection.