CVE-2026-31790 | OpenSSL up to 3.0.19/3.3.6/3.4.4/3.5.5/3.6.1 RSA KEM RSASVE Encapsulation RSA_public_encrypt uninitialized pointer (EUVD-2026-19969 / Nessus ID 305682)
A vulnerability was found in OpenSSL up to 3.0.19/3.3.6/3.4.4/3.5.5/3.6.1. It has been declared as problematic. The affected element is the function RSA_public_encrypt of the component RSA KEM RSASVE Encapsulation. Executing a manipulation can lead to uninitialized pointer.
This vulnerability is registered as CVE-2026-31790. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.