CVE-2025-14831: excessive resource consumption when verifying specially crafted malicious certificates containing a
large number of name constraints and SANs (bsc#1257960).
CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being
case-sensitive (bsc#1263707).
CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange
(bsc#1263715).
CVE-2026-33845: integer overflow and heap overrun when parsing fragments with zero length and non-zero offset during
DTLS handshake (bsc#1263704).
CVE-2026-33846: heap overwrite during DTLS handshake fragment reassembly due to missing validations and checks
(bsc#1263705).
CVE-2026-42009: undefined behavior resulting in a DoS when handling DTLS packets with duplicate sequence numbers
(bsc#1263708).
CVE-2026-42010: authentication bypass when processing a PSK username with a NUL-character (bsc#1263709).
CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation
(bsc#1263710).
CVE-2026-42012: spoofing of legitimate services and sensitive information interception via specially crafted
certificates containing URIs or SRV SANs. (bsc#1263711).
CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712).
CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks
a protected authentication path (bsc#1263713).
CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714).