The security release are based and managed by RedHat.
Short answer: you don’t. RHEL 8 is in the maintenance phase of its lifecycle. You should not expect new versions of things for it, and only critical and important CVE mitigations, likely backported into existing versions.
Please check the link below:
https://access.redhat.com/articles/3628041
Also you can use another opensource of openssl from the community to reach the security requirements or scans of security.
If it was helpful, please accept the answer.
Thank you,
Lisboa