What CVE identifier was assigned to the 2014 Heartbleed security bug?
Answer
CVE-2014-0160
Answer
CVE-2014-0160
The 2014 Heartbleed security bug was assigned the identifier CVE-2014-0160.
Heartbleed was a serious information-disclosure vulnerability in certain versions of OpenSSL, the widely used software library that helped secure internet connections. It affected the implementation of the TLS and DTLS heartbeat extensions, allowing a malicious request to read data from a server’s memory.
The bug could expose fragments such as usernames, passwords, session cookies, and private keys, although its exact impact depended on the vulnerable system and what happened to be in memory. OpenSSL released a fix in April 2014, and website operators were advised to update systems and replace potentially exposed credentials and certificates.
Heartbleed was not a weakness in the mathematical design of TLS itself. It was a programming error in an implementation. The distinctive name and heart-shaped logo helped make the technical issue broadly known, while the CVE identifier provided the precise reference used by security teams and databases.
Source: Wikipedia · fact-checked Sept. 2026