CVE-2026-77696: OpenSSL

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm.

Affected products

  • OpenSSL OpenSSL: from 1.1.1, before 1.1.1zj (fixed in 1.1.1zj); from 3.0.0, before 3.0.23 (fixed in 3.0.23); from 3.4.0, before 3.4.8 (fixed in 3.4.8); from 3.5.0, before 3.5.9 (fixed in 3.5.9); from 3.6.0, before 3.6.5 (fixed in 3.6.5); from 4.0.0, before 4.0.3 (fixed in 4.0.3)

Published 2026-09-29. Last modified 2026-10-08.