Search

Find a vulnerability

Search criteria

    707 vulnerabilities found for OpenSSL by OpenSSL

    CERTFR-2026-AVI-1241

    Vulnerability from certfr_avis - Published: 2026-09-30 - Updated: 2026-09-30

    De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    OpenSSL OpenSSL OpenSSL versions 3.6.x antérieures à 3.6.5
    OpenSSL OpenSSL OpenSSL versions 3.5.x antérieures à 3.5.9
    OpenSSL OpenSSL OpenSSL versions 1.0.2x antérieures à 1.0.2zs
    OpenSSL OpenSSL OpenSSL versions 1.1.1x antérieures à 1.1.1zj
    OpenSSL OpenSSL OpenSSL versions 3.0.x antérieures à 3.0.23
    OpenSSL OpenSSL OpenSSL versions 4.0.x antérieures à 4.0.3
    OpenSSL OpenSSL OpenSSL versions 3.4.x antérieures à 3.4.8
    References
    Bulletin de sécurité OpenSSL 2026-09-29 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "OpenSSL versions 3.6.x ant\u00e9rieures \u00e0 3.6.5",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 3.5.x ant\u00e9rieures \u00e0 3.5.9",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 1.0.2x ant\u00e9rieures \u00e0 1.0.2zs",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 1.1.1x ant\u00e9rieures \u00e0 1.1.1zj",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 3.0.x ant\u00e9rieures \u00e0 3.0.23",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 4.0.x ant\u00e9rieures \u00e0 4.0.3",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 3.4.x ant\u00e9rieures \u00e0 3.4.8",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-75806",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75806"
        },
        {
          "name": "CVE-2026-77696",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77696"
        },
        {
          "name": "CVE-2026-35189",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35189"
        },
        {
          "name": "CVE-2026-84784",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84784"
        },
        {
          "name": "CVE-2026-84783",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84783"
        },
        {
          "name": "CVE-2026-54875",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54875"
        },
        {
          "name": "CVE-2026-42772",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42772"
        },
        {
          "name": "CVE-2026-54873",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54873"
        },
        {
          "name": "CVE-2026-72897",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72897"
        },
        {
          "name": "CVE-2026-54872",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54872"
        },
        {
          "name": "CVE-2026-75805",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75805"
        },
        {
          "name": "CVE-2026-35191",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35191"
        },
        {
          "name": "CVE-2026-75804",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75804"
        },
        {
          "name": "CVE-2026-84782",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84782"
        }
      ],
      "initial_release_date": "2026-09-30T00:00:00",
      "last_revision_date": "2026-09-30T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1241",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-30T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans OpenSSL. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans OpenSSL",
      "vendor_advisories": [
        {
          "published_at": "2026-09-29",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenSSL",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ]
    }

    CERTFR-2026-AVI-1079

    Vulnerability from certfr_avis - Published: 2026-08-26 - Updated: 2026-08-26

    De multiples vulnérabilités ont été découvertes dans OpenSSL. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    OpenSSL OpenSSL OpenSSL versions 3.6.x antérieures à 3.6.4
    OpenSSL OpenSSL OpenSSL versions 3.4.x antérieures à 3.4.7
    OpenSSL OpenSSL OpenSSL versions 3.5.x antérieures à 3.5.8
    OpenSSL OpenSSL OpenSSL versions 3.0.x antérieures à 3.0.22
    OpenSSL OpenSSL OpenSSL versions 1.0.2x antérieures à 1.0.2zr
    OpenSSL OpenSSL OpenSSL versions 1.1.1x antérieures à 1.1.1zi
    OpenSSL OpenSSL OpenSSL versions 4.0.x antérieures à 4.0.2
    References
    Bulletin de sécurité OpenSSL 2026-08-25 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "OpenSSL versions 3.6.x ant\u00e9rieures \u00e0 3.6.4",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 3.4.x ant\u00e9rieures \u00e0 3.4.7",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 3.5.x ant\u00e9rieures \u00e0 3.5.8",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 3.0.x ant\u00e9rieures \u00e0 3.0.22",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 1.0.2x ant\u00e9rieures \u00e0 1.0.2zr",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 1.1.1x ant\u00e9rieures \u00e0 1.1.1zi",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        },
        {
          "description": "OpenSSL versions 4.0.x ant\u00e9rieures \u00e0 4.0.2",
          "product": {
            "name": "OpenSSL",
            "vendor": {
              "name": "OpenSSL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-63074",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63074"
        },
        {
          "name": "CVE-2026-63073",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63073"
        },
        {
          "name": "CVE-2026-14457",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14457"
        },
        {
          "name": "CVE-2026-63075",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63075"
        },
        {
          "name": "CVE-2026-63076",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63076"
        },
        {
          "name": "CVE-2026-18798",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18798"
        },
        {
          "name": "CVE-2026-75803",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75803"
        },
        {
          "name": "CVE-2026-54874",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54874"
        },
        {
          "name": "CVE-2026-63072",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63072"
        }
      ],
      "initial_release_date": "2026-08-26T00:00:00",
      "last_revision_date": "2026-08-26T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1079",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-08-26T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans OpenSSL. Elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans OpenSSL",
      "vendor_advisories": [
        {
          "published_at": "2026-08-25",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenSSL",
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        }
      ]
    }

    CVE-2026-84784 (GCVE-0-2026-84784)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:44
    VLAI
    Title
    QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
    Summary
    Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:43 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84784",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:43:47.766260Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:44:09.766Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Alexandr Nedvedicky"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A malicious remote peer may flood the local QUIC\u003cbr\u003estack with NEW_CONNECTION_ID frames by avoiding a limit check on\u003cbr\u003ehow many connection IDs the remote QUIC stack can use.\u003cbr\u003e\u003cbr\u003eImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\u003cbr\u003efor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\u003cbr\u003eframe is dispatched via the Control Frame Queue (CFQ). If the remote\u003cbr\u003epeer also withholds ACKs, then it can force the local stack\u003cbr\u003eto allocate ~400MB (depending on ACK delay).\u003cbr\u003e\u003cbr\u003eCWE: CWE-770: Allocation of Resources Without Limits or Throttling\u003cbr\u003e\u003cbr\u003eDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\u003cbr\u003eby which a remote peer can notify the local QUIC stack to change the\u003cbr\u003edestination connection ID (a.k.a. CID) the local stack uses to\u003cbr\u003eidentify the connection at the remote peer. Each CID is associated\u003cbr\u003ewith a sequence number. The sequence number is transmitted\u003cbr\u003ein NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\u003cbr\u003ewhich is being either associated with a connection or retired.\u003cbr\u003e\u003cbr\u003eThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\u003cbr\u003ea new CID is being associated with an existing connection. The\u003cbr\u003eNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\u003cbr\u003eretire-prior-to number. The retire-prior-to identifies existing\u003cbr\u003eCIDs that are to be retired. The local QUIC stack must send a\u003cbr\u003eRETIRE_CONNECTION_ID for every destination CID whose sequence number\u003cbr\u003eis less than retire-prior-to. The CID becomes retired after the\u003cbr\u003elocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\u003cbr\u003e\u003cbr\u003eAlthough the OpenSSL QUIC stack supports at most one destination CID\u003cbr\u003efor every connection, it can be tricked into processing more than\u003cbr\u003eone RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\u003cbr\u003estack currently retires the destination CID as soon as it receives\u003cbr\u003ethe NEW_CONNECTION_ID, while in fact the destination CID must\u003cbr\u003ebe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\u003cbr\u003eCorrecting the flawed logic also fixes the backlog growth.\u003cbr\u003e\u003cbr\u003e[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as the QUIC implementation is outside of\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:25.758Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "QUIC: Unbounded RETIRE_CONNECTION_ID Backlog",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-84784",
        "datePublished": "2026-09-29T15:32:25.758Z",
        "dateReserved": "2026-09-02T10:14:02.262Z",
        "dateUpdated": "2026-09-29T16:44:09.766Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84783 (GCVE-0-2026-84783)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:42
    VLAI
    Title
    Use-After-Free in X.509 Extension Cache Under Concurrent Use
    Summary
    Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:42 UTC
    CWE
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84783",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:42:36.722506Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:42:41.306Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Tim Becker (Xint.io)"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "aydinmercan"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Bob Beck"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The first concurrent use of the same X.509 certificate by\u003cbr\u003eseveral threads may cause its cached extension data to be freed while\u003cbr\u003eanother thread is still using it.\u003cbr\u003e\u003cbr\u003eImpact summary: A remote, unauthenticated peer could crash a multi-threaded\u003cbr\u003eTLS client, or a multi-threaded TLS server that requests client\u003cbr\u003ecertificates, if the first certificate chains built to the same trusted CA\u003cbr\u003ecertificate are built by several connections at the same time. This is a\u003cbr\u003euse-after-free read, which is likely to crash the process, resulting in a\u003cbr\u003eDenial of Service.\u003cbr\u003e\u003cbr\u003eCWE: CWE-416: Use After Free\u003cbr\u003e\u003cbr\u003eDescription: OpenSSL caches the decoded values of a certificate\u0027s X.509v3\u003cbr\u003eextensions inside the X509 object the first time they are needed. In\u003cbr\u003eOpenSSL 4.0 this cache is built in two phases: the extension values are\u003cbr\u003ecomputed while holding a read lock on the certificate, and the results are\u003cbr\u003ethen installed into the certificate under a write lock. Because a read lock\u003cbr\u003edoes not exclude other readers, several threads can compute the cache for\u003cbr\u003ethe same certificate at the same time. Each thread that subsequently\u003cbr\u003eacquires the write lock installs its own results and frees the values\u003cbr\u003einstalled by the thread before it, even though that earlier thread has\u003cbr\u003ealready marked the cache as complete and may have returned pointers into it\u003cbr\u003eto its caller. A caller still using those pointers then reads freed memory.\u003cbr\u003e\u003cbr\u003eAny certificate shared between threads is exposed the first time its\u003cbr\u003eextensions are decoded. In TLS the certificates at risk are the trusted CA\u003cbr\u003ecertificates supplied for chain verification, by whatever means, since these\u003cbr\u003eare shared by every connection and their extensions are decoded and cached\u003cbr\u003ethe first time a chain is built to them. Certificates sent by the peer are\u003cbr\u003edecoded separately for each connection and are not shared, so they are not\u003cbr\u003eaffected. In a TLS client verifying server certificates, or a TLS server\u003cbr\u003ethat requests and verifies client certificates, the use-after-free could\u003cbr\u003eonly occur if the first chains built to the same trusted CA are built by\u003cbr\u003eseveral connections at the same time.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as X.509 certificate handling is outside\u003cbr\u003eof the OpenSSL FIPS module boundary.\u003cbr\u003e\u003cbr\u003eOpenSSL 4.0 is vulnerable to this issue.\u003cbr\u003e\u003cbr\u003eOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\u003cbr\u003e\u003cbr\u003eOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\u003cbr\u003e\u003cbr\u003eThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\u003cbr\u003eindependently in a public report on 31 August 2026 by aydinmercan.\u003cbr\u003e\u003cbr\u003eThe fix has been developed by Bob Beck.\u003cbr\u003e\u003cbr\u003e-- cut (non-publishing metadata for internal use) --\u003cbr\u003eReported by: Tim Becker (Xint.io), aydinmercan\u003cbr\u003eFixed by: Bob Beck"
                }
              ],
              "value": "Issue summary: The first concurrent use of the same X.509 certificate by\nseveral threads may cause its cached extension data to be freed while\nanother thread is still using it.\n\nImpact summary: A remote, unauthenticated peer could crash a multi-threaded\nTLS client, or a multi-threaded TLS server that requests client\ncertificates, if the first certificate chains built to the same trusted CA\ncertificate are built by several connections at the same time. This is a\nuse-after-free read, which is likely to crash the process, resulting in a\nDenial of Service.\n\nCWE: CWE-416: Use After Free\n\nDescription: OpenSSL caches the decoded values of a certificate\u0027s X.509v3\nextensions inside the X509 object the first time they are needed. In\nOpenSSL 4.0 this cache is built in two phases: the extension values are\ncomputed while holding a read lock on the certificate, and the results are\nthen installed into the certificate under a write lock. Because a read lock\ndoes not exclude other readers, several threads can compute the cache for\nthe same certificate at the same time. Each thread that subsequently\nacquires the write lock installs its own results and frees the values\ninstalled by the thread before it, even though that earlier thread has\nalready marked the cache as complete and may have returned pointers into it\nto its caller. A caller still using those pointers then reads freed memory.\n\nAny certificate shared between threads is exposed the first time its\nextensions are decoded. In TLS the certificates at risk are the trusted CA\ncertificates supplied for chain verification, by whatever means, since these\nare shared by every connection and their extensions are decoded and cached\nthe first time a chain is built to them. Certificates sent by the peer are\ndecoded separately for each connection and are not shared, so they are not\naffected. In a TLS client verifying server certificates, or a TLS server\nthat requests and verifies client certificates, the use-after-free could\nonly occur if the first chains built to the same trusted CA are built by\nseveral connections at the same time.\n\nFIPS impact: no\nThe FIPS module is not affected as X.509 certificate handling is outside\nof the OpenSSL FIPS module boundary.\n\nOpenSSL 4.0 is vulnerable to this issue.\n\nOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\n\nThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\nindependently in a public report on 31 August 2026 by aydinmercan.\n\nThe fix has been developed by Bob Beck.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Tim Becker (Xint.io), aydinmercan\nFixed by: Bob Beck"
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Moderate"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "CWE-416 Use After Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:24.699Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/de97a1a54f43edefd43b5084ecac54ecadb33081"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Use-After-Free in X.509 Extension Cache Under Concurrent Use",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-84783",
        "datePublished": "2026-09-29T15:32:24.699Z",
        "dateReserved": "2026-09-02T10:14:02.262Z",
        "dateUpdated": "2026-09-29T16:42:41.306Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84782 (GCVE-0-2026-84782)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:45
    VLAI
    Title
    DTLS Retransmits Handshake Messages From a Stale Buffer Offset
    Summary
    Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:45 UTC
    CWE
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Affected: 1.0.2 , < 1.0.2zs (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.2,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84782",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:45:35.833483Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:45:40.378Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "1.0.2zs",
                  "status": "affected",
                  "version": "1.0.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Laurent Gaffie (secorizon.com)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Ryan Hooper"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The DTLS retransmission logic does not correctly handle\u003cbr\u003ea handshake message write that is suspended part-way through.\u003cbr\u003eThe retransmitted message can be read past the message buffer and\u003cbr\u003ethe retransmission overwrites the internal state the suspended write\u003cbr\u003eneeds to resume correctly.\u003cbr\u003e\u003cbr\u003eImpact summary: The retransmitted message can disclose a heap memory\u003cbr\u003eto the peer as plaintext handshake data or cause a crash and a Denial\u003cbr\u003eof Service when the read reaches an unmapped memory region.\u003cbr\u003e\u003cbr\u003eCWE: CWE-125: Out-of-bounds Read\u003cbr\u003e\u003cbr\u003eDescription: DTLS handshake messages can be written out in multiple\u003cbr\u003efragments, and a write can suspend mid-message (returning WANT_WRITE)\u003cbr\u003eif the underlying transport temporarily cannot accept more data. While\u003cbr\u003esuch a write is suspended, the DTLS retransmission timer may\u003cbr\u003eindependently fire and ask the retransmission logic to resend an\u003cbr\u003eearlier, already-acknowledged-as-sent message from its retransmit\u003cbr\u003equeue.\u003cbr\u003e\u003cbr\u003eThe retransmission logic reused the same internal buffer and position\u003cbr\u003etracking as the message that was still being written, without\u003cbr\u003eresetting the position back to the start of the message being\u003cbr\u003eretransmitted. As a result the retransmission was read starting from\u003cbr\u003ewherever the suspended write had left off, producing a mislabelled\u003cbr\u003emessage whose body was leftover bytes from the other, larger message\u003cbr\u003estill in flight - content that was never meant to be sent at that\u003cbr\u003epoint, and which could run past the end of the allocated buffer.\u003cbr\u003e\u003cbr\u003eSeparately, even when the retransmission is positioned correctly,\u003cbr\u003eallowing it to run to completion while another write is suspended\u003cbr\u003eoverwrites the same shared bookkeeping that the suspended write\u003cbr\u003edepends on to resume. When the application later resumes the\u003cbr\u003esuspended write (via a subsequent SSL_read(), SSL_write(),\u003cbr\u003eSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\u003cbr\u003estate inconsistent with the message and aborts the process in\u003cbr\u003ea debugging build.\u003cbr\u003e\u003cbr\u003eThe fix resets the retransmission\u0027s read position to the start of the\u003cbr\u003emessage before resending, and skips retransmission entirely whenever a\u003cbr\u003ehandshake write is still suspended, deferring to the next call that\u003cbr\u003eresumes it instead.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe affected code is outside the FIPS module boundary."
                }
              ],
              "value": "Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission\u0027s read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "High"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:23.605Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "DTLS Retransmits Handshake Messages From a Stale Buffer Offset",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-84782",
        "datePublished": "2026-09-29T15:32:23.605Z",
        "dateReserved": "2026-09-02T10:14:02.262Z",
        "dateUpdated": "2026-09-29T16:45:40.378Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77696 (GCVE-0-2026-77696)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:51
    VLAI
    Title
    Timing Side-Channel in SM2 Signature Generation
    Summary
    Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:51 UTC
    CWE
    • CWE-208 - Observable Timing Discrepancy
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77696",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:51:30.070097Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:51:33.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Vladimir Tokarev"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Igor Ustinov"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Viktor Dukhovni"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: SM2 signature generation uses non-constant-time arithmetic\u003cbr\u003eon secret values, forming a timing side-channel.\u003cbr\u003e\u003cbr\u003eImpact summary: An attacker able to measure SM2 signing times may learn\u003cbr\u003einformation about the per-signature secret nonce, which over many signatures\u003cbr\u003ecan, via a lattice / Hidden Number Problem attack, lead to recovery of the\u003cbr\u003eprivate key.\u003cbr\u003e\u003cbr\u003eCWE: CWE-208: Observable Timing Discrepancy\u003cbr\u003e\u003cbr\u003eDescription: SM2 signature generation computes the signature value using\u003cbr\u003evariable-time BIGNUM operations on the secret nonce and the private key, so\u003cbr\u003ethe time taken to produce an SM2 signature depends on these secret values,\u003cbr\u003eforming a timing side-channel.\u003cbr\u003e\u003cbr\u003eApplications performing SM2 signature generation are affected on all\u003cbr\u003eplatforms.\u003cbr\u003e\u003cbr\u003eFIPS Impact: no\u003cbr\u003eSM2 is not a FIPS algorithm."
                }
              ],
              "value": "Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "CWE-208 Observable Timing Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:22.520Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Timing Side-Channel in SM2 Signature Generation",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-77696",
        "datePublished": "2026-09-29T15:32:22.520Z",
        "dateReserved": "2026-08-21T07:47:36.032Z",
        "dateUpdated": "2026-09-29T16:51:33.618Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75806 (GCVE-0-2026-75806)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:53
    VLAI
    Title
    Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
    Summary
    Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:52 UTC
    CWE
    • CWE-1284 - Improper Validation of Specified Quantity in Input
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75806",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:52:47.298458Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:53:23.785Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Mounir Idrassi"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Mounir Idrassi"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\u003cbr\u003ecan be terminated by a single unauthenticated datagram whose encrypted\u003cbr\u003efragment is shorter than the mandatory explicit IV and authentication tag\u003cbr\u003eoverhead.\u003cbr\u003e\u003cbr\u003eImpact summary: An attacker who can send a datagram that is routed to an\u003cbr\u003eexisting DTLS 1.2 association can tear that association down without knowing\u003cbr\u003eany key material. This is a Denial of Service limited to the targeted\u003cbr\u003eassociation. There is no memory safety or confidentiality impact.\u003cbr\u003e\u003cbr\u003eCWE: CWE-1284: Improper Validation of Specified Quantity in Input\u003cbr\u003e\u003cbr\u003eDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\u003cbr\u003esuite carries an explicit IV followed by the ciphertext and an authentication\u003cbr\u003etag. When decrypting such a record the record layer passed the record length to\u003cbr\u003ethe cipher implementation before checking that the record was long enough to\u003cbr\u003econtain the explicit IV and the tag. For a record shorter than that overhead the\u003cbr\u003ecipher implementation rejected the impossible length, and the record layer\u003cbr\u003etreated this as an internal failure and raised a fatal internal_error alert\u003cbr\u003einstead of treating the record as one that failed authentication.\u003cbr\u003e\u003cbr\u003eIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\u003cbr\u003eexpected bad_record_mac alert. Since any undecryptable record already\u003cbr\u003eterminates a TLS connection, this is a protocol conformance issue rather than\u003cbr\u003ea security issue in TLS.\u003cbr\u003e\u003cbr\u003eThe fix validates the record length against the explicit IV and tag length\u003cbr\u003ebefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\u003cbr\u003esilently discards the record.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe affected code is outside the FIPS module boundary."
                }
              ],
              "value": "Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1284",
                  "description": "CWE-1284 Improper Validation of Specified Quantity in Input",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:21.457Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-75806",
        "datePublished": "2026-09-29T15:32:21.457Z",
        "dateReserved": "2026-08-18T09:34:32.659Z",
        "dateUpdated": "2026-09-29T16:53:23.785Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75805 (GCVE-0-2026-75805)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:54
    VLAI
    Title
    NULL Pointer Dereference in CMP Client Revocation Response Handling
    Summary
    Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:54 UTC
    CWE
    • CWE-476 - NULL-pointer dereference
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75805",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:54:03.315064Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:54:39.263Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Norbert Pocs"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A CMP client that requests certificate revocation on the basis\u003cbr\u003eof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\u003cbr\u003eprocessing a crafted revocation response. \u003cbr\u003e\u003cbr\u003eImpact summary: The NULL pointer dereference happens on a read which \u003cbr\u003eleads to a crash and a Denial of Service for the affected client application.\u003cbr\u003e\u003cbr\u003eCWE: CWE-476: NULL-pointer dereference\u003cbr\u003e\u003cbr\u003eDescription: A CMP client revoking a certificate has to tell the server which\u003cbr\u003ecertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\u003cbr\u003ecertificate itself or its issuer name and serial number. This is\u003cbr\u003e\u0027openssl cmp -cmd rr -csr \u003cfile\u003e\u0027 on the command line, or\u003cbr\u003eOSSL_CMP_exec_RR_ses() with the certificate supplied via\u003cbr\u003eOSSL_CMP_CTX_set1_p10CSR() through the API.\u003cbr\u003e\u003cbr\u003eA CSR does not contain the issuer name and serial number of the certificate,\u003cbr\u003eso the client does not send them. A server may optionally name the\u003cbr\u003ecertificate it revoked in its response, and the client then compares that\u003cbr\u003ename against what it sent. Having sent neither an issuer name nor a serial\u003cbr\u003enumber, it has nothing to compare against, and a server returning a specially\u003cbr\u003ecrafted name causes the client to read from a NULL pointer and crash.\u003cbr\u003e\u003cbr\u003eThe revocation response is checked for valid message protection before\u003cbr\u003ethe affected code is reached, so an attacker must be a malicious or\u003cbr\u003ecompromised CMP server, or a man-in-the-middle in possession of the\u003cbr\u003esecret used for message protection. Clients that identify the certificate\u003cbr\u003eto be revoked by a certificate or by issuer and serial number rather\u003cbr\u003ethan by a PKCS#10 CSR are not affected.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eNo FIPS modules are affected by this issue, as the CMP protocol\u003cbr\u003eimplementation is outside the OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n\u0027openssl cmp -cmd rr -csr \u003cfile\u003e\u0027 on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL-pointer dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:20.408Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "NULL Pointer Dereference in CMP Client Revocation Response Handling",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-75805",
        "datePublished": "2026-09-29T15:32:20.408Z",
        "dateReserved": "2026-08-18T09:34:32.659Z",
        "dateUpdated": "2026-09-29T16:54:39.263Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75804 (GCVE-0-2026-75804)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 17:15
    VLAI
    Title
    QUIC Connection-Level Flow Control is Not Enforced for Streams
    Summary
    Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:15 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75804",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:15:09.218928Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:15:40.043Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Moltenbit"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Saiyowa Security Team"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Alexandr Nedvedicky"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: OpenSSL QUIC stack does not enforce connection\u003cbr\u003elevel flow control for streams. Remote peers may send more bytes\u003cbr\u003eas long as they fit within the stream flow control limits.\u003cbr\u003e\u003cbr\u003eImpact summary: A malicious remote peer may exploit the lack of connection\u003cbr\u003eflow control for streams to make the QUIC stack receive ~100MB of memory\u003cbr\u003einstead of 768 KiB (default flow control window size).\u003cbr\u003e\u003cbr\u003eCWE: CWE-770: Allocation of Resources Without Limits or Throttling\u003cbr\u003e\u003cbr\u003eDescription: The local QUIC stack advertises two flow control limits\u003cbr\u003eto its remote peer: stream flow control limit and connection flow\u003cbr\u003econtrol limit. The remote peer must follow both limits when transmitting\u003cbr\u003estream data.\u003cbr\u003e\u003cbr\u003eWhenever the local QUIC stack receives a stream frame, it validates\u003cbr\u003ethat the size of the received stream frame stays within flow control limits.\u003cbr\u003eIf either limit is exceeded (stream level or connection level), then\u003cbr\u003ethe QUIC stack must close the connection with a flow control error.\u003cbr\u003e\u003cbr\u003eThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\u003cbr\u003ethe connection-level limit. To exploit the issue, three conditions must be met:\u003cbr\u003e  - the remote peer opens several streams\u003cbr\u003e  - each stream must stay within the stream-level flow control limit\u003cbr\u003e  - there must be no zero-offset byte sent on any of the streams\u003cbr\u003e    (to prevent the vulnerable QUIC stack from consuming data).\u003cbr\u003eBy meeting the conditions above, the remote peer may make the local stack\u003cbr\u003eallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\u003cbr\u003eof memory. MAX_STREAMS defaults to 100, and the limit applies to both\u003cbr\u003ebidirectional and unidirectional streams, making it 200 in total. The default\u003cbr\u003eflow control window for a stream is 512kB. The remote peer may\u003cbr\u003eforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as the QUIC implementation is outside of\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:19.335Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "QUIC Connection-Level Flow Control is Not Enforced for Streams",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-75804",
        "datePublished": "2026-09-29T15:32:19.335Z",
        "dateReserved": "2026-08-18T09:34:32.659Z",
        "dateUpdated": "2026-09-29T17:15:40.043Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-72897 (GCVE-0-2026-72897)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 17:16
    VLAI
    Title
    Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
    Summary
    Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:16 UTC
    CWE
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-72897",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:16:29.979390Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:16:38.842Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Filipe Casal (Trail of Bits)"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Brandon Luo"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Luigino Camastra (Aisle Research)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Matt Caswell"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\u003cbr\u003econnection to a different SSL_CTX part way through a handshake may access\u003cbr\u003ememory beyond the end of an internal array if the replacement context knows\u003cbr\u003eabout more provider signature algorithms than the context the connection was\u003cbr\u003ecreated from. Applications which never call SSL_set_SSL_CTX() are not\u003cbr\u003eaffected.\u003cbr\u003e\u003cbr\u003eImpact summary: A remote peer may be able to cause a small out-of-bounds\u003cbr\u003eread, and in some circumstances a fixed-value out-of-bounds write, on the\u003cbr\u003eserver heap. This may lead to a Denial of Service.\u003cbr\u003e\u003cbr\u003eCWE: CWE-787: Out-of-bounds Write\u003cbr\u003e\u003cbr\u003eDescription: A TLS connection records how many certificate slots it has\u003cbr\u003ewhen it is created, taken from the SSL_CTX that created it: the built-in\u003cbr\u003ecertificate types plus one slot for each provider TLS-SIGALG entry that\u003cbr\u003econtext was aware of. That count sizes an internal array of per-slot\u003cbr\u003ecertificate validity flags.\u003cbr\u003e\u003cbr\u003eAn application may replace a connection\u0027s SSL_CTX part way through the\u003cbr\u003ehandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\u003cbr\u003ecallback in order to serve a different virtual host. Doing so did not\u003cbr\u003erefresh the recorded count. A provider signature algorithm\u0027s slot index is\u003cbr\u003eits position in the list of whichever context resolves it, so if the\u003cbr\u003ereplacement context is aware of more of them than the original, an\u003cbr\u003ealgorithm offered by the peer can resolve to an index beyond the end of the\u003cbr\u003earray. Processing the peer\u0027s signature algorithms then reads one four byte\u003cbr\u003eword past the end for each such algorithm and, where the word read is zero,\u003cbr\u003ewrites a fixed value over it. A peer offering many of them can corrupt heap\u003cbr\u003emetadata and abort the process.\u003cbr\u003e\u003cbr\u003eOnly provider signature algorithms which occupy one of the excess slots,\u003cbr\u003eand which the server also has configured, have this effect. Codepoints the\u003cbr\u003ereplacement context does not recognise are discarded without being resolved\u003cbr\u003eto a slot, and provider signature algorithms are usable only from TLS 1.3.\u003cbr\u003e\u003cbr\u003eThe two contexts must therefore be aware of different numbers of provider\u003cbr\u003esignature algorithms, which requires separate library contexts, a provider\u003cbr\u003eloaded between the two being created, or providers which differ in what\u003cbr\u003ethey advertise - in 4.0, for example, the default provider advertises SM2\u003cbr\u003ewhere the FIPS provider does not. A deployment meeting the condition is\u003cbr\u003ealso unable to negotiate the affected algorithms with legitimate clients,\u003cbr\u003esince the same stale count hides the corresponding certificates, so the\u003cbr\u003emisconfiguration is likely to be noticed. For that reason, and because the\u003cbr\u003econfiguration is not the default, this issue has been assessed as Low\u003cbr\u003eseverity.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eNo FIPS modules are affected by this issue as the affected code is outside\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection\u0027s SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm\u0027s slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer\u0027s signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:18.277Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-72897",
        "datePublished": "2026-09-29T15:32:18.277Z",
        "dateReserved": "2026-08-10T17:02:46.613Z",
        "dateUpdated": "2026-09-29T17:16:38.842Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54875 (GCVE-0-2026-54875)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 17:17
    VLAI
    Title
    Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
    Summary
    Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:17 UTC
    CWE
    • CWE-208 - Observable Timing Discrepancy
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54875",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:17:05.164162Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:17:20.483Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Abhinav Agarwal"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Feng Xue"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Igor Ustinov"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A non-constant-time optimized implementation of scalar\u003cbr\u003epoint multiplication is used for SM2 private key operations on ARM64 and\u003cbr\u003eRISC-V platforms.\u003cbr\u003e\u003cbr\u003eImpact summary: An attacker able to measure the time taken by, or to observe\u003cbr\u003ethe cache-line access pattern of SM2 signing or decryption on an affected\u003cbr\u003eplatform can learn information about the secret scalar.\u003cbr\u003e\u003cbr\u003eCWE: CWE-208: Observable Timing Discrepancy\u003cbr\u003e\u003cbr\u003eDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\u003cbr\u003escalar multiplication implementation whose conditional branches and table\u003cbr\u003elook ups are chosen according to the bits of the secret scalar. The execution\u003cbr\u003etime and the cache-access pattern therefore depend on the long-term private\u003cbr\u003ekey (during SM2 decryption) or the per-signature nonce (during SM2 signature\u003cbr\u003egeneration), forming a timing and cache side-channel.\u003cbr\u003e\u003cbr\u003eFIPS Impact: no\u003cbr\u003eSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\u003cbr\u003eof the FIPS module.\u003cbr\u003e\u003cbr\u003eOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\u003cbr\u003eRISC-V.\u003cbr\u003e\u003cbr\u003eOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\u003cbr\u003e\u003cbr\u003eOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\u003cbr\u003eOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\u003cbr\u003eOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\u003cbr\u003eOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\u003cbr\u003e\u003cbr\u003eThis issue was reported on 2 May 2026 by Abhinav Agarwal.\u003cbr\u003eIt was independently reported on 6 June 2026 by Feng Xue.\u003cbr\u003eThe fix was developed by Igor Ustinov.\u003cbr\u003e\u003cbr\u003e-- cut (non-publishing metadata for internal use) --\u003cbr\u003eReported by: Abhinav Agarwal, Feng Xue\u003cbr\u003eFixed by: Igor Ustinov"
                }
              ],
              "value": "Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "CWE-208 Observable Timing Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:17.206Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-54875",
        "datePublished": "2026-09-29T15:32:17.206Z",
        "dateReserved": "2026-06-16T10:18:08.636Z",
        "dateUpdated": "2026-09-29T17:17:20.483Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54873 (GCVE-0-2026-54873)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-30 20:11
    VLAI
    Title
    QUIC STREAM Fragment Metadata DoS
    Summary
    Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:18 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54873",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:18:10.966747Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:11:09.162Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Zhen Yan (AntAISecurityLab)"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Alexandr Nedvedicky"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: QUIC process may keep memory for QUIC packet\u003cbr\u003ebuffer for much longer period than necessary.\u003cbr\u003e\u003cbr\u003eImpact summary: Remote peer can exploit this vulnerability\u003cbr\u003eby sending maliciously crafted packets, making the local\u003cbr\u003eQUIC stack to keep the memory for packet buffers allocated.\u003cbr\u003eThe time for which the memory remains allocated is entirely\u003cbr\u003eunder the control of the potentially malicious remote peer.\u003cbr\u003e\u003cbr\u003eCWE: CWE-770: Allocation of Resources Without Limits or Throttling\u003cbr\u003e\u003cbr\u003eDescription: To save copy operation from the packet buffer to the\u003cbr\u003estream reassemble buffer the QUIC stack leaves the stream data\u003cbr\u003eon the packet buffer waiting to be copied to a buffer provided\u003cbr\u003eby the local receiving application. The QUIC stack releases\u003cbr\u003ea reference to the packet buffer only after the data are copied\u003cbr\u003eto the application buffer. This design is more efficient for\u003cbr\u003elegitimate data transfers but enables an attacker to allocate a lot\u003cbr\u003emore memory than actually required by the data kept in the receiving\u003cbr\u003estream buffer.\u003cbr\u003e\u003cbr\u003eTo mitigate the vulnerability, the QUIC stack now calculates\u003cbr\u003eand monitors memory overhead for every stream. The memory overhead\u003cbr\u003efor a single stream frame is calculated as a difference between the\u003cbr\u003esize of the whole packet that carries the stream frame and the size\u003cbr\u003eof the stream frame itself. The memory overhead for a single stream\u003cbr\u003eframe is added to the total (cumulative) memory overhead QUIC stack\u003cbr\u003ekeeps for each stream. Once the cumulative memory overhead exceeds\u003cbr\u003e64kB, the QUIC stack moves the stream frame data from the packet\u003cbr\u003ebuffer to the stream buffer, starting with the next packet received.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as the QUIC implementation is outside of\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:16.134Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "QUIC STREAM Fragment Metadata DoS",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-54873",
        "datePublished": "2026-09-29T15:32:16.134Z",
        "dateReserved": "2026-06-16T10:18:08.635Z",
        "dateUpdated": "2026-09-30T20:11:09.162Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54872 (GCVE-0-2026-54872)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-29 17:28
    VLAI
    Title
    Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
    Summary
    Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:27 UTC
    CWE
    • CWE-208 - Observable Timing Discrepancy
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Affected: 1.0.2 , < 1.0.2zs (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54872",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:27:46.959054Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:28:12.657Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "1.0.2zs",
                  "status": "affected",
                  "version": "1.0.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Igor Ustinov"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The generic elliptic-curve scalar multiplication used for\u003cbr\u003eECDSA and SM2 signature operations with curves that do not have a dedicated\u003cbr\u003eimplementation leaks information about the secret nonce through timing.\u003cbr\u003e\u003cbr\u003eImpact summary: An attacker able to measure signing times may learn\u003cbr\u003einformation about the per-signature secret nonce, which over many signatures\u003cbr\u003ecan, via a lattice / Hidden Number Problem attack, lead to recovery of the\u003cbr\u003eprivate key.\u003cbr\u003e\u003cbr\u003eCWE: CWE-208: Observable Timing Discrepancy\u003cbr\u003e\u003cbr\u003eDescription: The generic elliptic-curve scalar multiplication used for\u003cbr\u003ecurves that do not have a dedicated constant-time implementation pads the\u003cbr\u003esecret scalar with non-constant-time BIGNUM operations, so the time taken\u003cbr\u003edepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\u003cbr\u003e\u003cbr\u003eThe leak is very small; observing it requires a large number of\u003cbr\u003emeasurements. The effect is largest for curves whose group order lies\u003cbr\u003eon a machine-word boundary, such as brainpoolP384r1.\u003cbr\u003e\u003cbr\u003eApplications using ECDSA signing over the Brainpool and other generic prime\u003cbr\u003ecurves, and SM2 signing on platforms that use the generic implementation,\u003cbr\u003eare vulnerable to this issue.\u003cbr\u003e\u003cbr\u003eThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\u003cbr\u003eimplementations and are not affected.\u003cbr\u003e\u003cbr\u003eFIPS Impact: no\u003cbr\u003eThe FIPS modules are not affected: the approved NIST curves used in the FIPS\u003cbr\u003eprovider have dedicated constant-time implementations and do not use the\u003cbr\u003eaffected code path."
                }
              ],
              "value": "Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "CWE-208 Observable Timing Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:15.075Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-54872",
        "datePublished": "2026-09-29T15:32:15.075Z",
        "dateReserved": "2026-06-16T10:18:08.635Z",
        "dateUpdated": "2026-09-29T17:28:12.657Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-42772 (GCVE-0-2026-42772)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-30 20:11
    VLAI
    Title
    Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
    Summary
    Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:35 UTC
    CWE
    • CWE-407 - Inefficient Algorithmic Complexity
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-42772",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:35:54.157005Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:11:09.295Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Saku0512"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Opal Wright (Trail of Bits)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Alexandr Nedvedicky"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The QUIC stream reassembly algorithm performance deteriorates\u003cbr\u003eprogressively as packets are arriving out of order. The worst case has\u003cbr\u003ea quadratic complexity proportional to the number of stream frames kept in\u003cbr\u003ethe buffer for the received stream data.\u003cbr\u003e\u003cbr\u003eImpact summary: A remote QUIC peer that completes the handshake can create\u003cbr\u003ea connection-scoped CPU pressure and potentially a Denial of Service using\u003cbr\u003ecompliant STREAM frames inside the advertised receive window, with low\u003cbr\u003eattacker bandwidth.\u003cbr\u003e\u003cbr\u003eCWE: CWE-407: Inefficient Algorithmic Complexity\u003cbr\u003e\u003cbr\u003eDescription: OpenSSL manages received QUIC stream fragments using a\u003cbr\u003edoubly-linked list. While it optimizes for append operations (at the end of\u003cbr\u003ethe list), it falls back to a head-to-tail linear search for any fragment\u003cbr\u003ethat does not immediately follow the current `tail`.\u003cbr\u003e\u003cbr\u003eBy manipulating the sequence of offsets, an attacker can force the server\u003cbr\u003eto perform O(n^2) operations, consuming excessive CPU time for the\u003cbr\u003eQUIC process.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as the QUIC implementation is outside of\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-407",
                  "description": "CWE-407 Inefficient Algorithmic Complexity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:14.009Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-42772",
        "datePublished": "2026-09-29T15:32:14.009Z",
        "dateReserved": "2026-04-29T09:22:27.969Z",
        "dateUpdated": "2026-09-30T20:11:09.295Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-35191 (GCVE-0-2026-35191)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-30 20:11
    VLAI
    Title
    QUIC Unvalidated Amplification Credit may be Over Accounted
    Summary
    Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:35 UTC
    CWE
    • CWE-440 - Expected Behavior Violation
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-35191",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:35:19.683843Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:11:09.437Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Ali Firas"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Nikolas Gauder (NVIDIA)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Neil Horman"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The OpenSSL QUIC server, when configured to not preform address\u003cbr\u003evalidation, can be forced to count incoming packets multiple times in its\u003cbr\u003eunvalidated credit computation, leading to a violation of the RFC 9000\u003cbr\u003eunvalidated connection amplification limit of 3 times the amount of data\u003cbr\u003ereceived.\u003cbr\u003e\u003cbr\u003eImpact summary: A remote attacker able to spoof packets to a server using the\u003cbr\u003eOpenSSL QUIC implementation might use the server for an amplification of\u003cbr\u003ea DDoS attack.\u003cbr\u003e\u003cbr\u003eCWE: CWE-440: Expected Behavior Violation \u003cbr\u003e\u003cbr\u003eDescription: OpenSSL\u0027s QUIC stack, when operating as a server, enforces client\u003cbr\u003eaddress validation (RFC 9000, Section 8), to confirm the peer address is not\u003cbr\u003eused for a traffic amplification attack.  If this feature is disabled on the\u003cbr\u003eserver, the QUIC stack limits the amount of server data that can be sent to 3\u003cbr\u003etimes the amount of data received from the peer address, until such time as the\u003cbr\u003eTLS handshake is completed.\u003cbr\u003e\u003cbr\u003eThe OpenSSL QUIC server, when operating in non-validation mode, adds the\u003cbr\u003elength of the whole datagram received to the unvalidated credit limit when\u003cbr\u003eprocessing each QUIC packet in the datagram. A remote peer may,\u003cbr\u003eafter establishing a connection with an initial client hello frame, send a\u003cbr\u003esubsequent datagram containing multiple QUIC packets, leading the server to\u003cbr\u003eaccount the entire datagram length for each packet in the datagram, resulting\u003cbr\u003ein the server believing that the peer has sent more data than it actually has,\u003cbr\u003ethereby violating the 3x amplification limit mandated by the RFC.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\u003cbr\u003eare affected by this CVE."
                }
              ],
              "value": "Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL\u0027s QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-440",
                  "description": "CWE-440 Expected Behavior Violation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:12.944Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "QUIC Unvalidated Amplification Credit may be Over Accounted",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-35191",
        "datePublished": "2026-09-29T15:32:12.944Z",
        "dateReserved": "2026-04-01T17:36:26.324Z",
        "dateUpdated": "2026-09-30T20:11:09.437Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-35189 (GCVE-0-2026-35189)

    Vulnerability from nvd – Published: 2026-09-29 15:32 – Updated: 2026-09-30 20:11
    VLAI
    Title
    Excessive Memory Allocation in Relative CRLDP Processing
    Summary
    Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:36 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Affected: 1.0.2 , < 1.0.2zs (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-35189",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:36:26.041392Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:11:09.577Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "1.0.2zs",
                  "status": "affected",
                  "version": "1.0.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Fuzz0x (ZKSC Institute of Security Research)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Viktor Dukhovni"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\u003cbr\u003edistribution points causes disproportionate heap growth when OpenSSL caches\u003cbr\u003eX.509 extensions.\u003cbr\u003e\u003cbr\u003eImpact summary: Receiving a crafted certificate from a malicious peer can lead\u003cbr\u003eto significant memory pressure and possible Denial of Service in clients or\u003cbr\u003ein servers that solicit client certificates.\u003cbr\u003e\u003cbr\u003eCWE: CWE-770: Allocation of Resources Without Limits or Throttling\u003cbr\u003e\u003cbr\u003eDescription: A certificate or a set of certificates that fits under the limit for\u003cbr\u003esize of certificates accepted from the peer (~100 KiB) can result in allocation\u003cbr\u003eof several hundred MiB of resident memory on the receiving side\u003cbr\u003eduring a normal TLS handshake.  This may be enough to crash the client or\u003cbr\u003eserver, if multiple concurrent connections lead to similarly large memory\u003cbr\u003eallocations.\u003cbr\u003e\u003cbr\u003eThe fix postpones processing of the CRL distribution points extensions in\u003cbr\u003ecertificates to the time when the processed value is required for CRL processing.\u003cbr\u003eThis avoids keeping large memory allocations for a long time when such\u003cbr\u003ecertificates are received.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe affected code is outside the FIPS module boundary."
                }
              ],
              "value": "Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:11.889Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Excessive Memory Allocation in Relative CRLDP Processing",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-35189",
        "datePublished": "2026-09-29T15:32:11.889Z",
        "dateReserved": "2026-04-01T17:36:26.323Z",
        "dateUpdated": "2026-09-30T20:11:09.577Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84784 (GCVE-0-2026-84784)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:44
    VLAI
    Title
    QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
    Summary
    Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:43 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84784",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:43:47.766260Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:44:09.766Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Alexandr Nedvedicky"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A malicious remote peer may flood the local QUIC\u003cbr\u003estack with NEW_CONNECTION_ID frames by avoiding a limit check on\u003cbr\u003ehow many connection IDs the remote QUIC stack can use.\u003cbr\u003e\u003cbr\u003eImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\u003cbr\u003efor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\u003cbr\u003eframe is dispatched via the Control Frame Queue (CFQ). If the remote\u003cbr\u003epeer also withholds ACKs, then it can force the local stack\u003cbr\u003eto allocate ~400MB (depending on ACK delay).\u003cbr\u003e\u003cbr\u003eCWE: CWE-770: Allocation of Resources Without Limits or Throttling\u003cbr\u003e\u003cbr\u003eDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\u003cbr\u003eby which a remote peer can notify the local QUIC stack to change the\u003cbr\u003edestination connection ID (a.k.a. CID) the local stack uses to\u003cbr\u003eidentify the connection at the remote peer. Each CID is associated\u003cbr\u003ewith a sequence number. The sequence number is transmitted\u003cbr\u003ein NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\u003cbr\u003ewhich is being either associated with a connection or retired.\u003cbr\u003e\u003cbr\u003eThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\u003cbr\u003ea new CID is being associated with an existing connection. The\u003cbr\u003eNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\u003cbr\u003eretire-prior-to number. The retire-prior-to identifies existing\u003cbr\u003eCIDs that are to be retired. The local QUIC stack must send a\u003cbr\u003eRETIRE_CONNECTION_ID for every destination CID whose sequence number\u003cbr\u003eis less than retire-prior-to. The CID becomes retired after the\u003cbr\u003elocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\u003cbr\u003e\u003cbr\u003eAlthough the OpenSSL QUIC stack supports at most one destination CID\u003cbr\u003efor every connection, it can be tricked into processing more than\u003cbr\u003eone RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\u003cbr\u003estack currently retires the destination CID as soon as it receives\u003cbr\u003ethe NEW_CONNECTION_ID, while in fact the destination CID must\u003cbr\u003ebe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\u003cbr\u003eCorrecting the flawed logic also fixes the backlog growth.\u003cbr\u003e\u003cbr\u003e[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as the QUIC implementation is outside of\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:25.758Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "QUIC: Unbounded RETIRE_CONNECTION_ID Backlog",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-84784",
        "datePublished": "2026-09-29T15:32:25.758Z",
        "dateReserved": "2026-09-02T10:14:02.262Z",
        "dateUpdated": "2026-09-29T16:44:09.766Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84783 (GCVE-0-2026-84783)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:42
    VLAI
    Title
    Use-After-Free in X.509 Extension Cache Under Concurrent Use
    Summary
    Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:42 UTC
    CWE
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84783",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:42:36.722506Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:42:41.306Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Tim Becker (Xint.io)"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "aydinmercan"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Bob Beck"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The first concurrent use of the same X.509 certificate by\u003cbr\u003eseveral threads may cause its cached extension data to be freed while\u003cbr\u003eanother thread is still using it.\u003cbr\u003e\u003cbr\u003eImpact summary: A remote, unauthenticated peer could crash a multi-threaded\u003cbr\u003eTLS client, or a multi-threaded TLS server that requests client\u003cbr\u003ecertificates, if the first certificate chains built to the same trusted CA\u003cbr\u003ecertificate are built by several connections at the same time. This is a\u003cbr\u003euse-after-free read, which is likely to crash the process, resulting in a\u003cbr\u003eDenial of Service.\u003cbr\u003e\u003cbr\u003eCWE: CWE-416: Use After Free\u003cbr\u003e\u003cbr\u003eDescription: OpenSSL caches the decoded values of a certificate\u0027s X.509v3\u003cbr\u003eextensions inside the X509 object the first time they are needed. In\u003cbr\u003eOpenSSL 4.0 this cache is built in two phases: the extension values are\u003cbr\u003ecomputed while holding a read lock on the certificate, and the results are\u003cbr\u003ethen installed into the certificate under a write lock. Because a read lock\u003cbr\u003edoes not exclude other readers, several threads can compute the cache for\u003cbr\u003ethe same certificate at the same time. Each thread that subsequently\u003cbr\u003eacquires the write lock installs its own results and frees the values\u003cbr\u003einstalled by the thread before it, even though that earlier thread has\u003cbr\u003ealready marked the cache as complete and may have returned pointers into it\u003cbr\u003eto its caller. A caller still using those pointers then reads freed memory.\u003cbr\u003e\u003cbr\u003eAny certificate shared between threads is exposed the first time its\u003cbr\u003eextensions are decoded. In TLS the certificates at risk are the trusted CA\u003cbr\u003ecertificates supplied for chain verification, by whatever means, since these\u003cbr\u003eare shared by every connection and their extensions are decoded and cached\u003cbr\u003ethe first time a chain is built to them. Certificates sent by the peer are\u003cbr\u003edecoded separately for each connection and are not shared, so they are not\u003cbr\u003eaffected. In a TLS client verifying server certificates, or a TLS server\u003cbr\u003ethat requests and verifies client certificates, the use-after-free could\u003cbr\u003eonly occur if the first chains built to the same trusted CA are built by\u003cbr\u003eseveral connections at the same time.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as X.509 certificate handling is outside\u003cbr\u003eof the OpenSSL FIPS module boundary.\u003cbr\u003e\u003cbr\u003eOpenSSL 4.0 is vulnerable to this issue.\u003cbr\u003e\u003cbr\u003eOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\u003cbr\u003e\u003cbr\u003eOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\u003cbr\u003e\u003cbr\u003eThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\u003cbr\u003eindependently in a public report on 31 August 2026 by aydinmercan.\u003cbr\u003e\u003cbr\u003eThe fix has been developed by Bob Beck.\u003cbr\u003e\u003cbr\u003e-- cut (non-publishing metadata for internal use) --\u003cbr\u003eReported by: Tim Becker (Xint.io), aydinmercan\u003cbr\u003eFixed by: Bob Beck"
                }
              ],
              "value": "Issue summary: The first concurrent use of the same X.509 certificate by\nseveral threads may cause its cached extension data to be freed while\nanother thread is still using it.\n\nImpact summary: A remote, unauthenticated peer could crash a multi-threaded\nTLS client, or a multi-threaded TLS server that requests client\ncertificates, if the first certificate chains built to the same trusted CA\ncertificate are built by several connections at the same time. This is a\nuse-after-free read, which is likely to crash the process, resulting in a\nDenial of Service.\n\nCWE: CWE-416: Use After Free\n\nDescription: OpenSSL caches the decoded values of a certificate\u0027s X.509v3\nextensions inside the X509 object the first time they are needed. In\nOpenSSL 4.0 this cache is built in two phases: the extension values are\ncomputed while holding a read lock on the certificate, and the results are\nthen installed into the certificate under a write lock. Because a read lock\ndoes not exclude other readers, several threads can compute the cache for\nthe same certificate at the same time. Each thread that subsequently\nacquires the write lock installs its own results and frees the values\ninstalled by the thread before it, even though that earlier thread has\nalready marked the cache as complete and may have returned pointers into it\nto its caller. A caller still using those pointers then reads freed memory.\n\nAny certificate shared between threads is exposed the first time its\nextensions are decoded. In TLS the certificates at risk are the trusted CA\ncertificates supplied for chain verification, by whatever means, since these\nare shared by every connection and their extensions are decoded and cached\nthe first time a chain is built to them. Certificates sent by the peer are\ndecoded separately for each connection and are not shared, so they are not\naffected. In a TLS client verifying server certificates, or a TLS server\nthat requests and verifies client certificates, the use-after-free could\nonly occur if the first chains built to the same trusted CA are built by\nseveral connections at the same time.\n\nFIPS impact: no\nThe FIPS module is not affected as X.509 certificate handling is outside\nof the OpenSSL FIPS module boundary.\n\nOpenSSL 4.0 is vulnerable to this issue.\n\nOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\n\nThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\nindependently in a public report on 31 August 2026 by aydinmercan.\n\nThe fix has been developed by Bob Beck.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Tim Becker (Xint.io), aydinmercan\nFixed by: Bob Beck"
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Moderate"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "CWE-416 Use After Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:24.699Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/de97a1a54f43edefd43b5084ecac54ecadb33081"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Use-After-Free in X.509 Extension Cache Under Concurrent Use",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-84783",
        "datePublished": "2026-09-29T15:32:24.699Z",
        "dateReserved": "2026-09-02T10:14:02.262Z",
        "dateUpdated": "2026-09-29T16:42:41.306Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84782 (GCVE-0-2026-84782)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:45
    VLAI
    Title
    DTLS Retransmits Handshake Messages From a Stale Buffer Offset
    Summary
    Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:45 UTC
    CWE
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Affected: 1.0.2 , < 1.0.2zs (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.2,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84782",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:45:35.833483Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:45:40.378Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "1.0.2zs",
                  "status": "affected",
                  "version": "1.0.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Laurent Gaffie (secorizon.com)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Ryan Hooper"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The DTLS retransmission logic does not correctly handle\u003cbr\u003ea handshake message write that is suspended part-way through.\u003cbr\u003eThe retransmitted message can be read past the message buffer and\u003cbr\u003ethe retransmission overwrites the internal state the suspended write\u003cbr\u003eneeds to resume correctly.\u003cbr\u003e\u003cbr\u003eImpact summary: The retransmitted message can disclose a heap memory\u003cbr\u003eto the peer as plaintext handshake data or cause a crash and a Denial\u003cbr\u003eof Service when the read reaches an unmapped memory region.\u003cbr\u003e\u003cbr\u003eCWE: CWE-125: Out-of-bounds Read\u003cbr\u003e\u003cbr\u003eDescription: DTLS handshake messages can be written out in multiple\u003cbr\u003efragments, and a write can suspend mid-message (returning WANT_WRITE)\u003cbr\u003eif the underlying transport temporarily cannot accept more data. While\u003cbr\u003esuch a write is suspended, the DTLS retransmission timer may\u003cbr\u003eindependently fire and ask the retransmission logic to resend an\u003cbr\u003eearlier, already-acknowledged-as-sent message from its retransmit\u003cbr\u003equeue.\u003cbr\u003e\u003cbr\u003eThe retransmission logic reused the same internal buffer and position\u003cbr\u003etracking as the message that was still being written, without\u003cbr\u003eresetting the position back to the start of the message being\u003cbr\u003eretransmitted. As a result the retransmission was read starting from\u003cbr\u003ewherever the suspended write had left off, producing a mislabelled\u003cbr\u003emessage whose body was leftover bytes from the other, larger message\u003cbr\u003estill in flight - content that was never meant to be sent at that\u003cbr\u003epoint, and which could run past the end of the allocated buffer.\u003cbr\u003e\u003cbr\u003eSeparately, even when the retransmission is positioned correctly,\u003cbr\u003eallowing it to run to completion while another write is suspended\u003cbr\u003eoverwrites the same shared bookkeeping that the suspended write\u003cbr\u003edepends on to resume. When the application later resumes the\u003cbr\u003esuspended write (via a subsequent SSL_read(), SSL_write(),\u003cbr\u003eSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\u003cbr\u003estate inconsistent with the message and aborts the process in\u003cbr\u003ea debugging build.\u003cbr\u003e\u003cbr\u003eThe fix resets the retransmission\u0027s read position to the start of the\u003cbr\u003emessage before resending, and skips retransmission entirely whenever a\u003cbr\u003ehandshake write is still suspended, deferring to the next call that\u003cbr\u003eresumes it instead.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe affected code is outside the FIPS module boundary."
                }
              ],
              "value": "Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission\u0027s read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "High"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:23.605Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "DTLS Retransmits Handshake Messages From a Stale Buffer Offset",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-84782",
        "datePublished": "2026-09-29T15:32:23.605Z",
        "dateReserved": "2026-09-02T10:14:02.262Z",
        "dateUpdated": "2026-09-29T16:45:40.378Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-77696 (GCVE-0-2026-77696)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:51
    VLAI
    Title
    Timing Side-Channel in SM2 Signature Generation
    Summary
    Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:51 UTC
    CWE
    • CWE-208 - Observable Timing Discrepancy
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77696",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:51:30.070097Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:51:33.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Vladimir Tokarev"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Igor Ustinov"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Viktor Dukhovni"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: SM2 signature generation uses non-constant-time arithmetic\u003cbr\u003eon secret values, forming a timing side-channel.\u003cbr\u003e\u003cbr\u003eImpact summary: An attacker able to measure SM2 signing times may learn\u003cbr\u003einformation about the per-signature secret nonce, which over many signatures\u003cbr\u003ecan, via a lattice / Hidden Number Problem attack, lead to recovery of the\u003cbr\u003eprivate key.\u003cbr\u003e\u003cbr\u003eCWE: CWE-208: Observable Timing Discrepancy\u003cbr\u003e\u003cbr\u003eDescription: SM2 signature generation computes the signature value using\u003cbr\u003evariable-time BIGNUM operations on the secret nonce and the private key, so\u003cbr\u003ethe time taken to produce an SM2 signature depends on these secret values,\u003cbr\u003eforming a timing side-channel.\u003cbr\u003e\u003cbr\u003eApplications performing SM2 signature generation are affected on all\u003cbr\u003eplatforms.\u003cbr\u003e\u003cbr\u003eFIPS Impact: no\u003cbr\u003eSM2 is not a FIPS algorithm."
                }
              ],
              "value": "Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "CWE-208 Observable Timing Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:22.520Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Timing Side-Channel in SM2 Signature Generation",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-77696",
        "datePublished": "2026-09-29T15:32:22.520Z",
        "dateReserved": "2026-08-21T07:47:36.032Z",
        "dateUpdated": "2026-09-29T16:51:33.618Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75806 (GCVE-0-2026-75806)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:53
    VLAI
    Title
    Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
    Summary
    Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:52 UTC
    CWE
    • CWE-1284 - Improper Validation of Specified Quantity in Input
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75806",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:52:47.298458Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:53:23.785Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Mounir Idrassi"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Mounir Idrassi"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\u003cbr\u003ecan be terminated by a single unauthenticated datagram whose encrypted\u003cbr\u003efragment is shorter than the mandatory explicit IV and authentication tag\u003cbr\u003eoverhead.\u003cbr\u003e\u003cbr\u003eImpact summary: An attacker who can send a datagram that is routed to an\u003cbr\u003eexisting DTLS 1.2 association can tear that association down without knowing\u003cbr\u003eany key material. This is a Denial of Service limited to the targeted\u003cbr\u003eassociation. There is no memory safety or confidentiality impact.\u003cbr\u003e\u003cbr\u003eCWE: CWE-1284: Improper Validation of Specified Quantity in Input\u003cbr\u003e\u003cbr\u003eDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\u003cbr\u003esuite carries an explicit IV followed by the ciphertext and an authentication\u003cbr\u003etag. When decrypting such a record the record layer passed the record length to\u003cbr\u003ethe cipher implementation before checking that the record was long enough to\u003cbr\u003econtain the explicit IV and the tag. For a record shorter than that overhead the\u003cbr\u003ecipher implementation rejected the impossible length, and the record layer\u003cbr\u003etreated this as an internal failure and raised a fatal internal_error alert\u003cbr\u003einstead of treating the record as one that failed authentication.\u003cbr\u003e\u003cbr\u003eIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\u003cbr\u003eexpected bad_record_mac alert. Since any undecryptable record already\u003cbr\u003eterminates a TLS connection, this is a protocol conformance issue rather than\u003cbr\u003ea security issue in TLS.\u003cbr\u003e\u003cbr\u003eThe fix validates the record length against the explicit IV and tag length\u003cbr\u003ebefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\u003cbr\u003esilently discards the record.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe affected code is outside the FIPS module boundary."
                }
              ],
              "value": "Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1284",
                  "description": "CWE-1284 Improper Validation of Specified Quantity in Input",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:21.457Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-75806",
        "datePublished": "2026-09-29T15:32:21.457Z",
        "dateReserved": "2026-08-18T09:34:32.659Z",
        "dateUpdated": "2026-09-29T16:53:23.785Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75805 (GCVE-0-2026-75805)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 16:54
    VLAI
    Title
    NULL Pointer Dereference in CMP Client Revocation Response Handling
    Summary
    Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 16:54 UTC
    CWE
    • CWE-476 - NULL-pointer dereference
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75805",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T16:54:03.315064Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:54:39.263Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Norbert Pocs"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A CMP client that requests certificate revocation on the basis\u003cbr\u003eof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\u003cbr\u003eprocessing a crafted revocation response. \u003cbr\u003e\u003cbr\u003eImpact summary: The NULL pointer dereference happens on a read which \u003cbr\u003eleads to a crash and a Denial of Service for the affected client application.\u003cbr\u003e\u003cbr\u003eCWE: CWE-476: NULL-pointer dereference\u003cbr\u003e\u003cbr\u003eDescription: A CMP client revoking a certificate has to tell the server which\u003cbr\u003ecertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\u003cbr\u003ecertificate itself or its issuer name and serial number. This is\u003cbr\u003e\u0027openssl cmp -cmd rr -csr \u003cfile\u003e\u0027 on the command line, or\u003cbr\u003eOSSL_CMP_exec_RR_ses() with the certificate supplied via\u003cbr\u003eOSSL_CMP_CTX_set1_p10CSR() through the API.\u003cbr\u003e\u003cbr\u003eA CSR does not contain the issuer name and serial number of the certificate,\u003cbr\u003eso the client does not send them. A server may optionally name the\u003cbr\u003ecertificate it revoked in its response, and the client then compares that\u003cbr\u003ename against what it sent. Having sent neither an issuer name nor a serial\u003cbr\u003enumber, it has nothing to compare against, and a server returning a specially\u003cbr\u003ecrafted name causes the client to read from a NULL pointer and crash.\u003cbr\u003e\u003cbr\u003eThe revocation response is checked for valid message protection before\u003cbr\u003ethe affected code is reached, so an attacker must be a malicious or\u003cbr\u003ecompromised CMP server, or a man-in-the-middle in possession of the\u003cbr\u003esecret used for message protection. Clients that identify the certificate\u003cbr\u003eto be revoked by a certificate or by issuer and serial number rather\u003cbr\u003ethan by a PKCS#10 CSR are not affected.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eNo FIPS modules are affected by this issue, as the CMP protocol\u003cbr\u003eimplementation is outside the OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n\u0027openssl cmp -cmd rr -csr \u003cfile\u003e\u0027 on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL-pointer dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:20.408Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "NULL Pointer Dereference in CMP Client Revocation Response Handling",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-75805",
        "datePublished": "2026-09-29T15:32:20.408Z",
        "dateReserved": "2026-08-18T09:34:32.659Z",
        "dateUpdated": "2026-09-29T16:54:39.263Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75804 (GCVE-0-2026-75804)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 17:15
    VLAI
    Title
    QUIC Connection-Level Flow Control is Not Enforced for Streams
    Summary
    Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:15 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75804",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:15:09.218928Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:15:40.043Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Moltenbit"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Saiyowa Security Team"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Alexandr Nedvedicky"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: OpenSSL QUIC stack does not enforce connection\u003cbr\u003elevel flow control for streams. Remote peers may send more bytes\u003cbr\u003eas long as they fit within the stream flow control limits.\u003cbr\u003e\u003cbr\u003eImpact summary: A malicious remote peer may exploit the lack of connection\u003cbr\u003eflow control for streams to make the QUIC stack receive ~100MB of memory\u003cbr\u003einstead of 768 KiB (default flow control window size).\u003cbr\u003e\u003cbr\u003eCWE: CWE-770: Allocation of Resources Without Limits or Throttling\u003cbr\u003e\u003cbr\u003eDescription: The local QUIC stack advertises two flow control limits\u003cbr\u003eto its remote peer: stream flow control limit and connection flow\u003cbr\u003econtrol limit. The remote peer must follow both limits when transmitting\u003cbr\u003estream data.\u003cbr\u003e\u003cbr\u003eWhenever the local QUIC stack receives a stream frame, it validates\u003cbr\u003ethat the size of the received stream frame stays within flow control limits.\u003cbr\u003eIf either limit is exceeded (stream level or connection level), then\u003cbr\u003ethe QUIC stack must close the connection with a flow control error.\u003cbr\u003e\u003cbr\u003eThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\u003cbr\u003ethe connection-level limit. To exploit the issue, three conditions must be met:\u003cbr\u003e  - the remote peer opens several streams\u003cbr\u003e  - each stream must stay within the stream-level flow control limit\u003cbr\u003e  - there must be no zero-offset byte sent on any of the streams\u003cbr\u003e    (to prevent the vulnerable QUIC stack from consuming data).\u003cbr\u003eBy meeting the conditions above, the remote peer may make the local stack\u003cbr\u003eallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\u003cbr\u003eof memory. MAX_STREAMS defaults to 100, and the limit applies to both\u003cbr\u003ebidirectional and unidirectional streams, making it 200 in total. The default\u003cbr\u003eflow control window for a stream is 512kB. The remote peer may\u003cbr\u003eforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as the QUIC implementation is outside of\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:19.335Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "QUIC Connection-Level Flow Control is Not Enforced for Streams",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-75804",
        "datePublished": "2026-09-29T15:32:19.335Z",
        "dateReserved": "2026-08-18T09:34:32.659Z",
        "dateUpdated": "2026-09-29T17:15:40.043Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-72897 (GCVE-0-2026-72897)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 17:16
    VLAI
    Title
    Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
    Summary
    Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:16 UTC
    CWE
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-72897",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:16:29.979390Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:16:38.842Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Filipe Casal (Trail of Bits)"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Brandon Luo"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Luigino Camastra (Aisle Research)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Matt Caswell"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\u003cbr\u003econnection to a different SSL_CTX part way through a handshake may access\u003cbr\u003ememory beyond the end of an internal array if the replacement context knows\u003cbr\u003eabout more provider signature algorithms than the context the connection was\u003cbr\u003ecreated from. Applications which never call SSL_set_SSL_CTX() are not\u003cbr\u003eaffected.\u003cbr\u003e\u003cbr\u003eImpact summary: A remote peer may be able to cause a small out-of-bounds\u003cbr\u003eread, and in some circumstances a fixed-value out-of-bounds write, on the\u003cbr\u003eserver heap. This may lead to a Denial of Service.\u003cbr\u003e\u003cbr\u003eCWE: CWE-787: Out-of-bounds Write\u003cbr\u003e\u003cbr\u003eDescription: A TLS connection records how many certificate slots it has\u003cbr\u003ewhen it is created, taken from the SSL_CTX that created it: the built-in\u003cbr\u003ecertificate types plus one slot for each provider TLS-SIGALG entry that\u003cbr\u003econtext was aware of. That count sizes an internal array of per-slot\u003cbr\u003ecertificate validity flags.\u003cbr\u003e\u003cbr\u003eAn application may replace a connection\u0027s SSL_CTX part way through the\u003cbr\u003ehandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\u003cbr\u003ecallback in order to serve a different virtual host. Doing so did not\u003cbr\u003erefresh the recorded count. A provider signature algorithm\u0027s slot index is\u003cbr\u003eits position in the list of whichever context resolves it, so if the\u003cbr\u003ereplacement context is aware of more of them than the original, an\u003cbr\u003ealgorithm offered by the peer can resolve to an index beyond the end of the\u003cbr\u003earray. Processing the peer\u0027s signature algorithms then reads one four byte\u003cbr\u003eword past the end for each such algorithm and, where the word read is zero,\u003cbr\u003ewrites a fixed value over it. A peer offering many of them can corrupt heap\u003cbr\u003emetadata and abort the process.\u003cbr\u003e\u003cbr\u003eOnly provider signature algorithms which occupy one of the excess slots,\u003cbr\u003eand which the server also has configured, have this effect. Codepoints the\u003cbr\u003ereplacement context does not recognise are discarded without being resolved\u003cbr\u003eto a slot, and provider signature algorithms are usable only from TLS 1.3.\u003cbr\u003e\u003cbr\u003eThe two contexts must therefore be aware of different numbers of provider\u003cbr\u003esignature algorithms, which requires separate library contexts, a provider\u003cbr\u003eloaded between the two being created, or providers which differ in what\u003cbr\u003ethey advertise - in 4.0, for example, the default provider advertises SM2\u003cbr\u003ewhere the FIPS provider does not. A deployment meeting the condition is\u003cbr\u003ealso unable to negotiate the affected algorithms with legitimate clients,\u003cbr\u003esince the same stale count hides the corresponding certificates, so the\u003cbr\u003emisconfiguration is likely to be noticed. For that reason, and because the\u003cbr\u003econfiguration is not the default, this issue has been assessed as Low\u003cbr\u003eseverity.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eNo FIPS modules are affected by this issue as the affected code is outside\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection\u0027s SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm\u0027s slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer\u0027s signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:18.277Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-72897",
        "datePublished": "2026-09-29T15:32:18.277Z",
        "dateReserved": "2026-08-10T17:02:46.613Z",
        "dateUpdated": "2026-09-29T17:16:38.842Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54875 (GCVE-0-2026-54875)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 17:17
    VLAI
    Title
    Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
    Summary
    Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:17 UTC
    CWE
    • CWE-208 - Observable Timing Discrepancy
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54875",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:17:05.164162Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:17:20.483Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Abhinav Agarwal"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Feng Xue"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Igor Ustinov"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A non-constant-time optimized implementation of scalar\u003cbr\u003epoint multiplication is used for SM2 private key operations on ARM64 and\u003cbr\u003eRISC-V platforms.\u003cbr\u003e\u003cbr\u003eImpact summary: An attacker able to measure the time taken by, or to observe\u003cbr\u003ethe cache-line access pattern of SM2 signing or decryption on an affected\u003cbr\u003eplatform can learn information about the secret scalar.\u003cbr\u003e\u003cbr\u003eCWE: CWE-208: Observable Timing Discrepancy\u003cbr\u003e\u003cbr\u003eDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\u003cbr\u003escalar multiplication implementation whose conditional branches and table\u003cbr\u003elook ups are chosen according to the bits of the secret scalar. The execution\u003cbr\u003etime and the cache-access pattern therefore depend on the long-term private\u003cbr\u003ekey (during SM2 decryption) or the per-signature nonce (during SM2 signature\u003cbr\u003egeneration), forming a timing and cache side-channel.\u003cbr\u003e\u003cbr\u003eFIPS Impact: no\u003cbr\u003eSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\u003cbr\u003eof the FIPS module.\u003cbr\u003e\u003cbr\u003eOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\u003cbr\u003eRISC-V.\u003cbr\u003e\u003cbr\u003eOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\u003cbr\u003e\u003cbr\u003eOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\u003cbr\u003eOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\u003cbr\u003eOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\u003cbr\u003eOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\u003cbr\u003e\u003cbr\u003eThis issue was reported on 2 May 2026 by Abhinav Agarwal.\u003cbr\u003eIt was independently reported on 6 June 2026 by Feng Xue.\u003cbr\u003eThe fix was developed by Igor Ustinov.\u003cbr\u003e\u003cbr\u003e-- cut (non-publishing metadata for internal use) --\u003cbr\u003eReported by: Abhinav Agarwal, Feng Xue\u003cbr\u003eFixed by: Igor Ustinov"
                }
              ],
              "value": "Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "CWE-208 Observable Timing Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:17.206Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-54875",
        "datePublished": "2026-09-29T15:32:17.206Z",
        "dateReserved": "2026-06-16T10:18:08.636Z",
        "dateUpdated": "2026-09-29T17:17:20.483Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54873 (GCVE-0-2026-54873)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-30 20:11
    VLAI
    Title
    QUIC STREAM Fragment Metadata DoS
    Summary
    Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:18 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54873",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:18:10.966747Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:11:09.162Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Zhen Yan (AntAISecurityLab)"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Bhabani Sankar Das"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Alexandr Nedvedicky"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: QUIC process may keep memory for QUIC packet\u003cbr\u003ebuffer for much longer period than necessary.\u003cbr\u003e\u003cbr\u003eImpact summary: Remote peer can exploit this vulnerability\u003cbr\u003eby sending maliciously crafted packets, making the local\u003cbr\u003eQUIC stack to keep the memory for packet buffers allocated.\u003cbr\u003eThe time for which the memory remains allocated is entirely\u003cbr\u003eunder the control of the potentially malicious remote peer.\u003cbr\u003e\u003cbr\u003eCWE: CWE-770: Allocation of Resources Without Limits or Throttling\u003cbr\u003e\u003cbr\u003eDescription: To save copy operation from the packet buffer to the\u003cbr\u003estream reassemble buffer the QUIC stack leaves the stream data\u003cbr\u003eon the packet buffer waiting to be copied to a buffer provided\u003cbr\u003eby the local receiving application. The QUIC stack releases\u003cbr\u003ea reference to the packet buffer only after the data are copied\u003cbr\u003eto the application buffer. This design is more efficient for\u003cbr\u003elegitimate data transfers but enables an attacker to allocate a lot\u003cbr\u003emore memory than actually required by the data kept in the receiving\u003cbr\u003estream buffer.\u003cbr\u003e\u003cbr\u003eTo mitigate the vulnerability, the QUIC stack now calculates\u003cbr\u003eand monitors memory overhead for every stream. The memory overhead\u003cbr\u003efor a single stream frame is calculated as a difference between the\u003cbr\u003esize of the whole packet that carries the stream frame and the size\u003cbr\u003eof the stream frame itself. The memory overhead for a single stream\u003cbr\u003eframe is added to the total (cumulative) memory overhead QUIC stack\u003cbr\u003ekeeps for each stream. Once the cumulative memory overhead exceeds\u003cbr\u003e64kB, the QUIC stack moves the stream frame data from the packet\u003cbr\u003ebuffer to the stream buffer, starting with the next packet received.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as the QUIC implementation is outside of\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:16.134Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "QUIC STREAM Fragment Metadata DoS",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-54873",
        "datePublished": "2026-09-29T15:32:16.134Z",
        "dateReserved": "2026-06-16T10:18:08.635Z",
        "dateUpdated": "2026-09-30T20:11:09.162Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54872 (GCVE-0-2026-54872)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-29 17:28
    VLAI
    Title
    Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
    Summary
    Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:27 UTC
    CWE
    • CWE-208 - Observable Timing Discrepancy
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Affected: 1.0.2 , < 1.0.2zs (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54872",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:27:46.959054Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:28:12.657Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "1.0.2zs",
                  "status": "affected",
                  "version": "1.0.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Igor Ustinov"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The generic elliptic-curve scalar multiplication used for\u003cbr\u003eECDSA and SM2 signature operations with curves that do not have a dedicated\u003cbr\u003eimplementation leaks information about the secret nonce through timing.\u003cbr\u003e\u003cbr\u003eImpact summary: An attacker able to measure signing times may learn\u003cbr\u003einformation about the per-signature secret nonce, which over many signatures\u003cbr\u003ecan, via a lattice / Hidden Number Problem attack, lead to recovery of the\u003cbr\u003eprivate key.\u003cbr\u003e\u003cbr\u003eCWE: CWE-208: Observable Timing Discrepancy\u003cbr\u003e\u003cbr\u003eDescription: The generic elliptic-curve scalar multiplication used for\u003cbr\u003ecurves that do not have a dedicated constant-time implementation pads the\u003cbr\u003esecret scalar with non-constant-time BIGNUM operations, so the time taken\u003cbr\u003edepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\u003cbr\u003e\u003cbr\u003eThe leak is very small; observing it requires a large number of\u003cbr\u003emeasurements. The effect is largest for curves whose group order lies\u003cbr\u003eon a machine-word boundary, such as brainpoolP384r1.\u003cbr\u003e\u003cbr\u003eApplications using ECDSA signing over the Brainpool and other generic prime\u003cbr\u003ecurves, and SM2 signing on platforms that use the generic implementation,\u003cbr\u003eare vulnerable to this issue.\u003cbr\u003e\u003cbr\u003eThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\u003cbr\u003eimplementations and are not affected.\u003cbr\u003e\u003cbr\u003eFIPS Impact: no\u003cbr\u003eThe FIPS modules are not affected: the approved NIST curves used in the FIPS\u003cbr\u003eprovider have dedicated constant-time implementations and do not use the\u003cbr\u003eaffected code path."
                }
              ],
              "value": "Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "CWE-208 Observable Timing Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:15.075Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-54872",
        "datePublished": "2026-09-29T15:32:15.075Z",
        "dateReserved": "2026-06-16T10:18:08.635Z",
        "dateUpdated": "2026-09-29T17:28:12.657Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-42772 (GCVE-0-2026-42772)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-30 20:11
    VLAI
    Title
    Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
    Summary
    Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:35 UTC
    CWE
    • CWE-407 - Inefficient Algorithmic Complexity
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-42772",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:35:54.157005Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:11:09.295Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Saku0512"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Opal Wright (Trail of Bits)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Alexandr Nedvedicky"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The QUIC stream reassembly algorithm performance deteriorates\u003cbr\u003eprogressively as packets are arriving out of order. The worst case has\u003cbr\u003ea quadratic complexity proportional to the number of stream frames kept in\u003cbr\u003ethe buffer for the received stream data.\u003cbr\u003e\u003cbr\u003eImpact summary: A remote QUIC peer that completes the handshake can create\u003cbr\u003ea connection-scoped CPU pressure and potentially a Denial of Service using\u003cbr\u003ecompliant STREAM frames inside the advertised receive window, with low\u003cbr\u003eattacker bandwidth.\u003cbr\u003e\u003cbr\u003eCWE: CWE-407: Inefficient Algorithmic Complexity\u003cbr\u003e\u003cbr\u003eDescription: OpenSSL manages received QUIC stream fragments using a\u003cbr\u003edoubly-linked list. While it optimizes for append operations (at the end of\u003cbr\u003ethe list), it falls back to a head-to-tail linear search for any fragment\u003cbr\u003ethat does not immediately follow the current `tail`.\u003cbr\u003e\u003cbr\u003eBy manipulating the sequence of offsets, an attacker can force the server\u003cbr\u003eto perform O(n^2) operations, consuming excessive CPU time for the\u003cbr\u003eQUIC process.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe FIPS module is not affected as the QUIC implementation is outside of\u003cbr\u003ethe OpenSSL FIPS module boundary."
                }
              ],
              "value": "Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-407",
                  "description": "CWE-407 Inefficient Algorithmic Complexity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:14.009Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-42772",
        "datePublished": "2026-09-29T15:32:14.009Z",
        "dateReserved": "2026-04-29T09:22:27.969Z",
        "dateUpdated": "2026-09-30T20:11:09.295Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-35191 (GCVE-0-2026-35191)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-30 20:11
    VLAI
    Title
    QUIC Unvalidated Amplification Credit may be Over Accounted
    Summary
    Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:35 UTC
    CWE
    • CWE-440 - Expected Behavior Violation
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-35191",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:35:19.683843Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:11:09.437Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Ali Firas"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "Nikolas Gauder (NVIDIA)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Neil Horman"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: The OpenSSL QUIC server, when configured to not preform address\u003cbr\u003evalidation, can be forced to count incoming packets multiple times in its\u003cbr\u003eunvalidated credit computation, leading to a violation of the RFC 9000\u003cbr\u003eunvalidated connection amplification limit of 3 times the amount of data\u003cbr\u003ereceived.\u003cbr\u003e\u003cbr\u003eImpact summary: A remote attacker able to spoof packets to a server using the\u003cbr\u003eOpenSSL QUIC implementation might use the server for an amplification of\u003cbr\u003ea DDoS attack.\u003cbr\u003e\u003cbr\u003eCWE: CWE-440: Expected Behavior Violation \u003cbr\u003e\u003cbr\u003eDescription: OpenSSL\u0027s QUIC stack, when operating as a server, enforces client\u003cbr\u003eaddress validation (RFC 9000, Section 8), to confirm the peer address is not\u003cbr\u003eused for a traffic amplification attack.  If this feature is disabled on the\u003cbr\u003eserver, the QUIC stack limits the amount of server data that can be sent to 3\u003cbr\u003etimes the amount of data received from the peer address, until such time as the\u003cbr\u003eTLS handshake is completed.\u003cbr\u003e\u003cbr\u003eThe OpenSSL QUIC server, when operating in non-validation mode, adds the\u003cbr\u003elength of the whole datagram received to the unvalidated credit limit when\u003cbr\u003eprocessing each QUIC packet in the datagram. A remote peer may,\u003cbr\u003eafter establishing a connection with an initial client hello frame, send a\u003cbr\u003esubsequent datagram containing multiple QUIC packets, leading the server to\u003cbr\u003eaccount the entire datagram length for each packet in the datagram, resulting\u003cbr\u003ein the server believing that the peer has sent more data than it actually has,\u003cbr\u003ethereby violating the 3x amplification limit mandated by the RFC.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\u003cbr\u003eare affected by this CVE."
                }
              ],
              "value": "Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL\u0027s QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-440",
                  "description": "CWE-440 Expected Behavior Violation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:12.944Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "QUIC Unvalidated Amplification Credit may be Over Accounted",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-35191",
        "datePublished": "2026-09-29T15:32:12.944Z",
        "dateReserved": "2026-04-01T17:36:26.324Z",
        "dateUpdated": "2026-09-30T20:11:09.437Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-35189 (GCVE-0-2026-35189)

    Vulnerability from cvelistv5 – Published: 2026-09-29 15:32 – Updated: 2026-09-30 20:11
    VLAI
    Title
    Excessive Memory Allocation in Relative CRLDP Processing
    Summary
    Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:36 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenSSL OpenSSL Affected: 4.0.0 , < 4.0.3 (semver)
    Affected: 3.6.0 , < 3.6.5 (semver)
    Affected: 3.5.0 , < 3.5.9 (semver)
    Affected: 3.4.0 , < 3.4.8 (semver)
    Affected: 3.0.0 , < 3.0.23 (semver)
    Affected: 1.1.1 , < 1.1.1zj (custom)
    Affected: 1.0.2 , < 1.0.2zs (custom)
    Create a notification for this product.
    Date Public
    2026-09-29 14:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-35189",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:36:26.041392Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:11:09.577Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenSSL",
              "vendor": "OpenSSL",
              "versions": [
                {
                  "lessThan": "4.0.3",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.6.5",
                  "status": "affected",
                  "version": "3.6.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.5.9",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.4.8",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.0.23",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "1.1.1zj",
                  "status": "affected",
                  "version": "1.1.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "1.0.2zs",
                  "status": "affected",
                  "version": "1.0.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Fuzz0x (ZKSC Institute of Security Research)"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "Viktor Dukhovni"
            }
          ],
          "datePublic": "2026-09-29T14:21:57.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\u003cbr\u003edistribution points causes disproportionate heap growth when OpenSSL caches\u003cbr\u003eX.509 extensions.\u003cbr\u003e\u003cbr\u003eImpact summary: Receiving a crafted certificate from a malicious peer can lead\u003cbr\u003eto significant memory pressure and possible Denial of Service in clients or\u003cbr\u003ein servers that solicit client certificates.\u003cbr\u003e\u003cbr\u003eCWE: CWE-770: Allocation of Resources Without Limits or Throttling\u003cbr\u003e\u003cbr\u003eDescription: A certificate or a set of certificates that fits under the limit for\u003cbr\u003esize of certificates accepted from the peer (~100 KiB) can result in allocation\u003cbr\u003eof several hundred MiB of resident memory on the receiving side\u003cbr\u003eduring a normal TLS handshake.  This may be enough to crash the client or\u003cbr\u003eserver, if multiple concurrent connections lead to similarly large memory\u003cbr\u003eallocations.\u003cbr\u003e\u003cbr\u003eThe fix postpones processing of the CRL distribution points extensions in\u003cbr\u003ecertificates to the time when the processed value is required for CRL processing.\u003cbr\u003eThis avoids keeping large memory allocations for a long time when such\u003cbr\u003ecertificates are received.\u003cbr\u003e\u003cbr\u003eFIPS impact: no\u003cbr\u003eThe affected code is outside the FIPS module boundary."
                }
              ],
              "value": "Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."
            }
          ],
          "metrics": [
            {
              "format": "other",
              "other": {
                "content": {
                  "text": "Low"
                },
                "type": "https://openssl-library.org/policies/general/security-policy/"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T15:32:11.889Z",
            "orgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
            "shortName": "openssl"
          },
          "references": [
            {
              "name": "OpenSSL Advisory",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openssl-library.org/news/secadv/20260929.txt"
            },
            {
              "name": "4.0.3 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84"
            },
            {
              "name": "3.6.5 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f"
            },
            {
              "name": "3.5.9 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89"
            },
            {
              "name": "3.4.8 git commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Excessive Memory Allocation in Relative CRLDP Processing",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "3a12439a-ef3a-4c79-92e6-6081a721f1e5",
        "assignerShortName": "openssl",
        "cveId": "CVE-2026-35189",
        "datePublished": "2026-09-29T15:32:11.889Z",
        "dateReserved": "2026-04-01T17:36:26.323Z",
        "dateUpdated": "2026-09-30T20:11:09.577Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }