Skip to content

Update OpenSSL (September 2026) #158010

Description

@zware

Feature or enhancement

Proposal:

OpenSSL will have updated releases, including 3.5.9 and (not publicly available) 3.0.23. The highest vulnerability level in this set is "high" and it is not yet known if we will be directly impacted, but we should update before the next round of our releases anyway.

OpenSSL 3.0 (still used by 3.13) is now EOL, so we will need to update 3.13 binaries to 3.5 as well, with RM @Yhg1s's understandably begrudging agreement obtained on Discord. I'll be going ahead with that update (to 3.5.8) before the new releases are available to give us as much time as possible to work out any issues arising from that and to make backporting the 3.5.8->3.5.9 update as smooth as possible.

Has this already been discussed elsewhere?

This is a minor feature, which does not need previous discussion elsewhere

Links to previous discussion of this feature:

See gh-156369, gh-151159, gh-149254 for previous rounds.

Linked PRs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

3.13bugs and security fixes3.14bugs and security fixes3.15pre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesOS-androidOS-iosOS-macOS-windowsdependenciesPull requests that update a dependency fileinfraCI, GitHub Actions, buildbots, Dependabot, etc.release-blockertopic-SSLtype-featureA feature request or enhancement

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions