CVE-2025-69418 | OpenSSL up to 3.6.0 Low-level OCB API levelCRYPTO_ocb128_encrypt missing cryptographic step (Nessus ID 296779 / WID-SEC-2026-0234)
A vulnerability marked as problematic has been reported in OpenSSL up to 3.6.0. Affected by this issue is the function levelCRYPTO_ocb128_encrypt of the component Low-level OCB API. The manipulation leads to missing cryptographic step.
This vulnerability is referenced as CVE-2025-69418. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.