Skip to content

CVE-2026-28389: Windows installer still bundles vulnerable OpenSSL #10294

@GROSJ033

Description

@GROSJ033

Describe the bug

Release 2.34.32 updated the bundled OpenSSL to 1.1.1zg for Linux installers, but the Windows MSI installer still ships with a vulnerable version of libssl-3.dll. Please apply the same OpenSSL update to the Windows build pipeline.

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

With Release 2.34.32 we expected the Windows Installer patch to be close behind.

Current Behavior

Vulnerability being reported as CVE-2026-28389

Reproduction Steps

NA

Possible Solution

No response

Additional Information/Context

No response

CLI version used

2.34.45

Environment details (OS name and version, etc.)

Windows Server 2019

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugThis issue is a bug.needs-triageThis issue or PR still needs to be triaged.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions