diff --git a/SOURCES/0020-curl-7.61.1-openssl-engines.patch b/SOURCES/0020-curl-7.61.1-openssl-engines.patch
new file mode 100644
index 0000000..d8c5579
--- /dev/null
+++ b/SOURCES/0020-curl-7.61.1-openssl-engines.patch
@@ -0,0 +1,33 @@
+From 032843be4cefcb163d15573d15a228680e771106 Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Mon, 24 Sep 2018 08:26:58 +0200
+Subject: [PATCH] openssl: load built-in engines too
+
+Regression since 38203f1
+
+Reported-by: Jean Fabrice
+Fixes #3023
+Closes #3040
+
+Upstream-commit: e2dd435d473cdc97785df95d032276fafb4b7746
+Signed-off-by: Kamil Dudka <kdudka@redhat.com>
+---
+ lib/vtls/openssl.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/lib/vtls/openssl.c b/lib/vtls/openssl.c
+index 78970d1..d8bcc4f 100644
+--- a/lib/vtls/openssl.c
++++ b/lib/vtls/openssl.c
+@@ -979,7 +979,7 @@ static int Curl_ossl_init(void)
+ 
+   OPENSSL_load_builtin_modules();
+ 
+-#ifdef HAVE_ENGINE_LOAD_BUILTIN_ENGINES
++#ifdef USE_OPENSSL_ENGINE
+   ENGINE_load_builtin_engines();
+ #endif
+ 
+-- 
+2.25.4
+
diff --git a/SPECS/curl.spec b/SPECS/curl.spec
index 707664f..7b8aceb 100644
--- a/SPECS/curl.spec
+++ b/SPECS/curl.spec
@@ -1,7 +1,7 @@
 Summary: A utility for getting files from remote servers (FTP, HTTP, and others)
 Name: curl
 Version: 7.61.1
-Release: 12%{?dist}
+Release: 13%{?dist}
 License: MIT
 Source: https://curl.haxx.se/download/%{name}-%{version}.tar.xz
 
@@ -52,6 +52,9 @@ Patch18:  0018-curl-7.65.3-CVE-2019-5482.patch
 # double free due to subsequent call of realloc() (CVE-2019-5481)
 Patch19:  0019-curl-7.65.3-CVE-2019-5481.patch
 
+# load built-in openssl engines (#1854369)
+Patch20:  0020-curl-7.61.1-openssl-engines.patch
+
 # patch making libcurl multilib ready
 Patch101: 0101-curl-7.32.0-multilib.patch
 
@@ -234,6 +237,7 @@ git apply %{PATCH4}
 %patch17 -p1
 %patch18 -p1
 %patch19 -p1
+%patch20 -p1
 
 # make tests/*.py use Python 3
 sed -e '1 s|^#!/.*python|#!%{__python3}|' -i tests/*.py
@@ -394,6 +398,9 @@ rm -f ${RPM_BUILD_ROOT}%{_libdir}/libcurl.la
 %{_libdir}/libcurl.so.4.[0-9].[0-9].minimal
 
 %changelog
+* Wed Jul 15 2020 Kamil Dudka <kdudka@redhat.com> - 7.61.1-13
+- load built-in openssl engines (#1854369)
+
 * Wed Sep 11 2019 Kamil Dudka <kdudka@redhat.com> - 7.61.1-12
 - double free due to subsequent call of realloc() (CVE-2019-5481)
 - fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)