CVE-2026-34181
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/06/2026
Last modified:
23/07/2026
Description
Issue Summary: The PKCS#12 file processing fails to perform sufficient input<br />
validation for files that use Password-Based Message Authentication Code 1<br />
(PBMAC1) integrity mechanism allowing a certificate and private key forgery.<br />
<br />
Impact Summary: An attacker impersonating a user can cause a service reading<br />
PKCS#12 files to accept forged certificates and private keys with a 1 in 256<br />
probability.<br />
<br />
If a service accepting PKCS#12 files is using passwords for authenticating<br />
the received files, the attacker can create unencrypted PKCS#12 files that<br />
use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing<br />
them to craft a file that will be accepted with a 1 in 256 probability.<br />
That would then cause the service to accept a certificate and private key<br />
controlled by the attacker.<br />
<br />
The FIPS modules are not affected by this issue, as the affected code is<br />
outside the OpenSSL FIPS module boundary.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | 3.4.0 (including) | 3.4.6 (excluding) |
| cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | 3.5.0 (including) | 3.5.7 (excluding) |
| cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | 3.6.0 (including) | 3.6.3 (excluding) |
| cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/openssl/openssl/commit/0300eb9ddce7a0895bf301a4b0c03a9da2313a0f
- https://github.com/openssl/openssl/commit/79eb76a937e474bb7610a0a3dc57131dc8dc6610
- https://github.com/openssl/openssl/commit/85dcbb3abaa4878af5c8fbbe11bce708fcf984a7
- https://github.com/openssl/openssl/commit/ec36f2417c4ddd8cabce4b4a60a3d7a7365f2d81
- https://openssl-library.org/news/secadv/20260609.txt



