OpenSSL Information Disclosure Vulnerability
n/a — n/a
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
7.5
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- None
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Published
- Apr 7, 2014
- Modified
- Jun 17, 2026
- Added to KEV
- May 4, 2022
- Federal patch due
- May 25, 2022
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2014-0160, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- FiloSottile/Heartbleed★ 2389
A checker (site and tool) for CVE-2014-0160
updated Jul 19, 2026
- musalbas/heartbleed-masstest★ 573
Multi-threaded tool for scanning many hosts for CVE-2014-0160.
updated Jun 26, 2026
- titanous/heartbleeder★ 452
OpenSSL CVE-2014-0160 Heartbleed vulnerability test
updated Jun 12, 2026
- Lekensteyn/pacemaker★ 330
Heartbleed (CVE-2014-0160) client exploit
updated Jun 14, 2026
- sensepost/heartbleed-poc★ 170
Test for SSL heartbeat vulnerability (CVE-2014-0160)
updated May 25, 2026
- einaros/heartbleed-tools★ 98
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.
updated Feb 21, 2026
- mpgn/heartbleed-PoC★ 85
:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:
updated Jun 11, 2026
- isgroup/openmagic★ 40
OpenSSL TLS heartbeat read overrun (CVE-2014-0160)
updated Jun 23, 2026
References
- advisories.mageia.org
- blog.fox-it.com
- cogentdatahub.com
- download.schneider-electric.com
- git.openssl.org
- heartbleed.com
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.opensuse.org
- lists.opensuse.org
- lists.opensuse.org
- marc.info
- marc.info
- marc.info
- marc.info
- marc.info
- marc.info
- marc.info
- marc.info
Frequently asked questions
What is CVE-2014-0160?
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
How severe is CVE-2014-0160?
CVE-2014-0160 has a CVSS base score of 7.5 out of 10 (CVSS 3.1).
Is CVE-2014-0160 actively exploited in the wild?
Yes. CVE-2014-0160 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 4, 2022, meaning CISA has confirmed evidence of active exploitation.
What is the EPSS score for CVE-2014-0160?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2014-0160?
We found 8 public GitHub repositories referencing CVE-2014-0160, though none matched a known Nuclei template or Metasploit module at last check. Review each one before relying on it - see the proof-of-concept section above.
What type of vulnerability is CVE-2014-0160?
CVE-2014-0160 is classified under CWE-125 (CWE-125 Out-of-bounds Read).
Cross-checked against
Impactr finds and proves whether CVE-2014-0160 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist