CVE-2026-75803
OpenSSL vulnerability analysis and mitigation

Overview

CVE-2026-75803 is a cryptographic vulnerability in Node.js where use of EVP_Cipher() can allow AEAD (Authenticated Encryption with Associated Data) message forgeries when the ciphertext is empty. The CVE is currently in Reserved status, meaning full technical details have not yet been publicly disclosed. It has been estimated as HIGH severity by Feedly's threat intelligence system, and was first detected by Nessus (plugin 338398) (Tenable). The vulnerability was inserted into Feedly's tracking system on 2026-08-20, with limited official information available at this time.

Technical details

The vulnerability stems from improper handling of empty ciphertext inputs when using OpenSSL's EVP_Cipher() API within Node.js, which can cause AEAD authentication tag verification to be bypassed or forged (CWE classification not yet officially assigned, but likely related to CWE-327: Use of a Broken or Risky Cryptographic Algorithm or CWE-347: Improper Verification of Cryptographic Signature). AEAD modes (such as AES-GCM) are designed to provide both confidentiality and integrity guarantees; a forgery vulnerability means an attacker may be able to craft or manipulate messages that pass authentication checks without possessing the correct key. The specific attack vector and preconditions — such as whether attacker-controlled input reaches the vulnerable code path — have not been fully disclosed, as the CVE remains in Reserved status (Tenable, Radar Offseq).

Impact

If successfully exploited, this vulnerability could allow an attacker to forge authenticated messages in applications relying on Node.js AEAD encryption, undermining the integrity guarantees of encrypted communications. This could lead to unauthorized data manipulation, bypass of message authentication checks, and potential confidentiality breaches depending on how the affected cryptographic operations are used in the target application. Applications using Node.js cryptographic APIs with AEAD ciphers (e.g., AES-GCM) and processing empty or attacker-controlled ciphertexts are most at risk (Radar Offseq).

Exploitability

As of the time of this report, CVE-2026-75803 is in Reserved status with no confirmed public exploit code, proof-of-concept, or in-the-wild exploitation reported. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No EPSS score or threat actor attribution is currently available. Feedly's assessment characterizes this as an "early-stage threat with insufficient data for impact assessment" and recommends monitoring for official disclosure and vendor guidance (Tenable).

Mitigation and workarounds

No official patch or vendor advisory has been published at this time, as the CVE remains in Reserved status. Organizations using Node.js should monitor the official Node.js security advisories and the CVE database for updates upon full disclosure. As a precautionary measure, review application code that uses Node.js cryptographic APIs with AEAD modes (particularly EVP_Cipher() or equivalent wrappers) and ensure that empty ciphertext inputs are explicitly rejected at the application layer. Keeping Node.js updated to the latest stable release is strongly recommended once a patched version is identified (Tenable, Vulners/Ubuntu).

Community reactions

Coverage of CVE-2026-75803 is currently limited given its Reserved status. Tenable has published a Nessus detection plugin (338398), and threat intelligence aggregators such as Radar Offseq and Vulners have begun tracking the vulnerability. No notable researcher commentary, vendor statements, or significant media coverage has emerged at this stage (Radar Offseq, Vulners/Ubuntu).

Additional resources


SourceThis report was generated using AI

Related OpenSSL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-11999HIGH8.2
  • OpenSSL logoOpenSSL
  • wolfssl
NoYesJun 25, 2026
CVE-2026-14456HIGH7.5
  • OpenSSL logoOpenSSL
  • edk2
NoYesAug 13, 2026
CVE-2026-54876HIGH7.5
  • OpenSSL logoOpenSSL
  • seal-openssl
NoYesAug 05, 2026
CVE-2026-45784MEDIUM5.1
  • Rust logoRust
  • rust-debuginfo
NoYesJul 17, 2026
CVE-2026-75803NONEN/A
  • OpenSSL logoOpenSSL
  • edk2
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management