OpenSSL 3.0.7 has been released to fix two buffer overflows in punycode decoding functions, specifically in X.509 certificate verification. The vulnerabilities, CVE-2022-3786 and CVE-2022-3602, were initially assessed as CRITICAL but later downgraded to HIGH after further testing. The issues can be triggered by connecting to a malicious server or by a CA signing a malicious certificate. Users of OpenSSL 3.0.0-3.0.6 are encouraged to upgrade to 3.0.7 as soon as possible.