CVE-2026-42767

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

Issue summary: An attacker-controlled CMP (Certificate Management Protocol)<br /> server could trigger a NULL pointer dereference in a CMP client application.<br /> <br /> Impact summary: A NULL pointer dereference causes a crash of the<br /> application and a Denial of Service.<br /> <br /> An attacker controlling a CMP server (or acting as a man-in-the-middle) could<br /> craft a CMP response containing a CRMF (Certificate Request Message Format)<br /> CertRepMessage with an EncryptedValue structure where the symmAlg field<br /> has an algorithm OID but no parameters field. When the OpenSSL CMP client<br /> processes this response, the NULL dereference occurs, causing a crash of<br /> the CMP client.<br /> <br /> Applications that process untrusted CMP/CRMF messages may be affected.<br /> <br /> The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this<br /> issue, as the affected code is outside the OpenSSL FIPS module boundary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.21 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.4.0 (including) 3.4.6 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.7 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.6.0 (including) 3.6.3 (excluding)
cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*