已验证65% 置信事实精确时间
2014年的Heartbleed漏洞揭示了OpenSSL这样被全球互联网依赖的项目仅由两名兼职维护者支撑
3
来源数
65%
置信度
中期 (~90 天)
时效性
2026/7/2
首次发现
有效期至:2026/9/30
来源
rsync遭AI代码入侵:36次提交引发开源基础设施信任危机
bilibiliAI老张同学2026/6/5
相关事实
已验证2014年的Heartbleed漏洞是OpenSSL加密库中存在了两年多的严重漏洞,影响了全球约17%的安全Web服务器83% 相似待验证在 2014 年 Heartbleed 漏洞爆出前,OpenSSL 核心维护者仅有一人,年度捐款不足两千美元78% 相似待验证The 2014 Heartbleed vulnerability in OpenSSL exposed the dire funding situation of core open-source maintainers77% 相似待验证Heartbleed漏洞在OpenSSL代码中存在了超过两年才被发现,直接催生了Core Infrastructure Initiative(CII,后演变为OpenSSF)的成立77% 相似待验证2014年的OpenSSL Heartbleed漏洞因边界检查缺失导致内存越界读取,攻击者可借此窃取服务器内存中的私钥和用户数据74% 相似
引用此条事实
Stable URI
https://kongchang.com/claim/53973API
curl https://kongchang.com/api/v1/knowledge/claims/53973MCP
get_claim(id=53973)