{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos-stream8els/vex/2025/cve-2025-66199-els_os-centos-stream8els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-02-09T14:45:45Z",
      "generator": {
        "date": "2026-02-09T14:45:45Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-66199-ELS_OS-CENTOS-STREAM8ELS",
      "initial_release_date": "2025-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2025-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-02-09T14:45:45Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-66199"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8",
                "product": {
                  "name": "Community Enterprise Operating System 8",
                  "product_id": "CentOS-Stream-8",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:1.1.1k-12.el8.x86_64",
                "product": {
                  "name": "openssl-1:1.1.1k-12.el8.x86_64",
                  "product_id": "openssl-1:1.1.1k-12.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/openssl@1.1.1k-12.el8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.1.1k-12.el8.x86_64",
                "product": {
                  "name": "openssl-devel-1:1.1.1k-12.el8.x86_64",
                  "product_id": "openssl-devel-1:1.1.1k-12.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/openssl-devel@1.1.1k-12.el8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.1.1k-12.el8.x86_64",
                "product": {
                  "name": "openssl-libs-1:1.1.1k-12.el8.x86_64",
                  "product_id": "openssl-libs-1:1.1.1k-12.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/openssl-libs@1.1.1k-12.el8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:1.1.1k-12.el8.x86_64",
                "product": {
                  "name": "openssl-perl-1:1.1.1k-12.el8.x86_64",
                  "product_id": "openssl-perl-1:1.1.1k-12.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/openssl-perl@1.1.1k-12.el8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.1.1k-12.el8.x86_64",
                "product": {
                  "name": "openssl-static-1:1.1.1k-12.el8.x86_64",
                  "product_id": "openssl-static-1:1.1.1k-12.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/openssl-static@1.1.1k-12.el8?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.1.1k-12.el8.i686",
                "product": {
                  "name": "openssl-devel-1:1.1.1k-12.el8.i686",
                  "product_id": "openssl-devel-1:1.1.1k-12.el8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/openssl-devel@1.1.1k-12.el8?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.1.1k-12.el8.i686",
                "product": {
                  "name": "openssl-libs-1:1.1.1k-12.el8.i686",
                  "product_id": "openssl-libs-1:1.1.1k-12.el8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/openssl-libs@1.1.1k-12.el8?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_id": "openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl@1.1.1k-12.el8.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                "product": {
                  "name": "openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_id": "openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl@1.1.1k-12.el8.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                "product": {
                  "name": "openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_id": "openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl@1.1.1k-12.el8.tuxcare.els3?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_id": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.1.1k-12.el8.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                "product": {
                  "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_id": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.1.1k-12.el8.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                "product": {
                  "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_id": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.1.1k-12.el8.tuxcare.els3?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_id": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.1.1k-12.el8.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                "product": {
                  "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_id": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.1.1k-12.el8.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                "product": {
                  "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_id": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.1.1k-12.el8.tuxcare.els3?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_id": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-perl@1.1.1k-12.el8.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                "product": {
                  "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_id": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-perl@1.1.1k-12.el8.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                "product": {
                  "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_id": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-perl@1.1.1k-12.el8.tuxcare.els3?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_id": "openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-static@1.1.1k-12.el8.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                "product": {
                  "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_id": "openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-static@1.1.1k-12.el8.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                "product": {
                  "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_id": "openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-static@1.1.1k-12.el8.tuxcare.els3?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686",
                "product": {
                  "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686",
                  "product_id": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.1.1k-12.el8.tuxcare.els1?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686",
                "product": {
                  "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686",
                  "product_id": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.1.1k-12.el8.tuxcare.els2?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686",
                "product": {
                  "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686",
                  "product_id": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-devel@1.1.1k-12.el8.tuxcare.els3?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686",
                "product": {
                  "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686",
                  "product_id": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.1.1k-12.el8.tuxcare.els1?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686",
                "product": {
                  "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686",
                  "product_id": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.1.1k-12.el8.tuxcare.els2?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686",
                "product": {
                  "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686",
                  "product_id": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl-libs@1.1.1k-12.el8.tuxcare.els3?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:1.1.1k-12.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.x86_64"
        },
        "product_reference": "openssl-1:1.1.1k-12.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64"
        },
        "product_reference": "openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64"
        },
        "product_reference": "openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686"
        },
        "product_reference": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.1.1k-12.el8.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.i686"
        },
        "product_reference": "openssl-devel-1:1.1.1k-12.el8.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.1.1k-12.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.x86_64"
        },
        "product_reference": "openssl-devel-1:1.1.1k-12.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686"
        },
        "product_reference": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64"
        },
        "product_reference": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686"
        },
        "product_reference": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64"
        },
        "product_reference": "openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686"
        },
        "product_reference": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.1.1k-12.el8.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.i686"
        },
        "product_reference": "openssl-libs-1:1.1.1k-12.el8.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.1.1k-12.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.x86_64"
        },
        "product_reference": "openssl-libs-1:1.1.1k-12.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686"
        },
        "product_reference": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64"
        },
        "product_reference": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686"
        },
        "product_reference": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64"
        },
        "product_reference": "openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:1.1.1k-12.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.x86_64"
        },
        "product_reference": "openssl-perl-1:1.1.1k-12.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64"
        },
        "product_reference": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64"
        },
        "product_reference": "openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.1.1k-12.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.x86_64"
        },
        "product_reference": "openssl-static-1:1.1.1k-12.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64"
        },
        "product_reference": "openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64"
        },
        "product_reference": "openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-66199",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: A TLS 1.3 connection using certificate compression can be\nforced to allocate a large buffer before decompression without checking\nagainst the configured certificate size limit.\nImpact summary: An attacker can cause per-connection memory allocations of\nup to approximately 22 MiB and extra CPU work, potentially leading to\nservice degradation or resource exhaustion (Denial of Service).\nIn affected configurations, the peer-supplied uncompressed certificate\nlength from a CompressedCertificate message is used to grow a heap buffer\nprior to decompression. This length is not bounded by the max_cert_list\nsetting, which otherwise constrains certificate message sizes. An attacker\ncan exploit this to cause large per-connection allocations followed by\nhandshake failure. No memory corruption or information disclosure occurs.\nThis issue only affects builds where TLS 1.3 certificate compression is\ncompiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression\nalgorithm (brotli, zlib, or zstd) is available, and where the compression\nextension is negotiated. Both clients receiving a server CompressedCertificate\nand servers in mutual TLS scenarios receiving a client CompressedCertificate\nare affected. Servers that do not request client certificates are not\nvulnerable to client-initiated attacks.\nUsers can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\nto disable receiving compressed certificates.\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the TLS implementation is outside the OpenSSL FIPS module boundary.\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
          "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
          "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.x86_64",
          "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.i686",
          "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686",
          "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686",
          "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
          "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686",
          "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
          "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.x86_64",
          "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.i686",
          "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686",
          "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686",
          "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
          "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686",
          "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
          "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.x86_64",
          "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
          "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
          "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.x86_64",
          "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
          "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
          "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-66199"
        }
      ],
      "release_date": "2026-01-27T00:00:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "CVE-2025-66199 is an availability-only condition with high attack complexity that increases per‑connection memory/CPU use but causes no memory corruption or data exposure. Exploitation requires TLS 1.3 certificate compression to be compiled in, at least one compression algorithm available, and the extension negotiated; servers that do not request client certificates are not susceptible to client‑initiated attacks, and receiving compressed certificates can be disabled via SSL_OP_NO_RX_CERTIFICATE_COMPRESSION. Only OpenSSL 3.3–3.6 builds are affected—OpenSSL 3.0, 1.1.1, and 1.0.2 are not—so exposure is inherently constrained.",
          "product_ids": [
            "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.x86_64",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.i686",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.x86_64",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.i686",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.x86_64",
            "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.x86_64",
            "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-1:1.1.1k-12.el8.x86_64",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.i686",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.i686",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.i686",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.i686",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-devel-1:1.1.1k-12.el8.x86_64",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.i686",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.i686",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.i686",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.i686",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-libs-1:1.1.1k-12.el8.x86_64",
            "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-perl-1:1.1.1k-12.el8.x86_64",
            "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.tuxcare.els3.x86_64",
            "CentOS-Stream-8:openssl-static-1:1.1.1k-12.el8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}