Skip to content

TablePlus 6.8.1 [Windows] contains vulnerable OpenSSL DLLs (v3.0.15) #771

@AScott-WWF

Description

@AScott-WWF

It has come to our attention that the latest Windows version of TablePlus (6.8.1) includes vulnerable OpenSSL 3.0.15 DLLs
Default install paths:
c:\program files\tableplus\cmd\libcrypto-3-x64.dll
c:\program files\tableplus\libcrypto-3-x64.dll
c:\program files\tableplus\libssl-3-x64.dll
c:\program files\tableplus\x64\libcrypto-3-x64.dll
c:\program files\tableplus\x64\libssl-3-x64.dll

This version of OpenSSL is vulnerable to the following 3 CVEs:

As OpenSSL 3.0.x goes end of life on the 7th September 2026, any OpenSSL 3.0.x use should be replaced with a supported version. Version 3.5 [LTS] is supported until 8th April 2030

Therefore please could you update the OpenSSL DLLs with either 3.0.18 (https://openssl-library.org/news/openssl-3.0-notes/) or 3.5.4 (https://openssl-library.org/news/openssl-3.5-notes/) to resolve these issues?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions