OpenSSL 4.0.3
OpenSSL 4.0.3 is a security release fixing 15 issues, including a use-after-free in the X.509 extension cache, a QUIC denial of service, and an elliptic curve timing side channel. OpenSSL 3.6.5, 3.5.9, and 3.4.8 shipped alongside.
Download TAR.GZ Project website ↗Download Mirrors
OpenSSL 4.0.3 was released on September 29, 2026 as a security release, fixing 15 issues. Maintenance releases for older branches came out the same day: 3.6.5, 3.5.9, and 3.4.8. We covered it in the news.
Notable fixes
| CVE | Issue |
|---|---|
| CVE-2026-84783 | Use-after-free in the X.509 extension cache under concurrency |
| CVE-2026-42772 | CPU denial of service through QUIC fragment reassembly |
| CVE-2026-54872 | Timing side channel for non-NIST elliptic curves |
| CVE-2026-72897 | Out-of-bounds access after SSL_set_SSL_CTX() during a handshake |
| CVE-2026-75805 | NULL dereference in CMP revocation response handling |
Plus fixes for DTLS, QUIC, SM2, and base64 regressions introduced in 4.0.
Do not build this to update your system
OpenSSL is a library that almost everything links against. Update it through your distribution, which backports these fixes to the version it ships, then restart services that use it:
openssl version
sudo apt update && sudo apt upgrade # Debian / Ubuntu
sudo dnf upgrade --refresh # Fedora / RHEL
sudo needrestart # Debian/Ubuntu: restart affected services
Building OpenSSL from source and installing it over the system copy can break your package manager and every program linked to it. The source tarball is for developers, packagers, and applications that bundle their own copy:
tar xf openssl-4.0.3.tar.gz && cd openssl-4.0.3
./Configure --prefix=/opt/openssl-4.0.3
make -j$(nproc) && make test
sudo make install
Our lsof guide shows how to find processes still using a deleted, pre-update library.
Verify Your Download
Each release on GitHub and the source page comes with SHA-256 checksums and PGP signatures from the OpenSSL release team.