YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0040

Register entry

OpenSSL stack overflow, invalid or NULL pointer in PKCS#12 PBMAC1 MAC verification, credited to Aisle Research

CVE
CVE-2025-11187
Project
OpenSSL
Component
PKCS#12 PBMAC1 MAC verification
Finder
AISLE
Autonomy
autonomous system per the company; OpenSSL credits named Aisle Research staff
Evidence tier
Claim outside the record
Assigner
openssl
Severity
Moderate (OpenSSL severity policy)
Bounty
None published
Confidence
CONFIRMED

What happened

One of four OpenSSL records of 27 January 2026 whose credits name people at Aisle Research; the claim that an autonomous system found them is the company's. AISLE says it holds all twelve CVEs in that coordinated release, a figure this desk has not confirmed at the record.

Credit as recorded: reporters: Stanislav Fort (Aisle Research), Petr Šimeček (Aisle Research), Hamza (Metadust); remediation developer: Tomáš Mráz. Date basis: datePublished.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026