
11/2/2022 · Evan Johnson, Michal Melewski
What this post added
This post details how Cloudflare's adoption of BoringSSL, rather than OpenSSL, renders it unaffected by critical OpenSSL vulnerabilities CVE-2022-3602 and CVE-2022-3786. It explains the nature of these vulnerabilities, their potential impact on clients and servers, and provides guidance on patching vulnerable OpenSSL instances. The key takeaway is Cloudflare's proactive security stance through its choice of cryptographic library.