CVE-2026-34054

vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set openssldir to a path on the build machine, making that path be attackable later on customer machines. This issue has been patched in version 3.6.1#3.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-31 03:15

Updated : 2026-06-17 10:38


NVD link : CVE-2026-34054

Mitre link : CVE-2026-34054

CVE.ORG link : CVE-2026-34054


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element