CVE-2025-11187 | OpenSSL up to 3.4.3/3.5.4/3.6.0 PKCS#12 File out-of-bounds write (Nessus ID 297022 / WID-SEC-2026-0234)
A vulnerability was found in OpenSSL up to 3.4.3/3.5.4/3.6.0. It has been declared as critical. The impacted element is an unknown function of the component PKCS#12 File Handler. The manipulation results in out-of-bounds write.
This vulnerability is known as CVE-2025-11187. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.