CVE-2017-8301: OpenBSD Libressl

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.

Affected products

  • OpenBSD Libressl: version 2.5.1 only; version 2.5.2 only; version 2.5.3 only

Published 2017-04-27. Last modified 2026-06-17.