CVE-2026-63074

Updated on 25 Aug 2026

Severity

Awaiting Analysis

Details

CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

A flaw was found in OpenSSL. The CMP (Certificate Management Protocol) implementation does not clear cached additional certificates when an invalid message is received, leading to excessive memory consumption. This allows a malicious client to repeatedly send requests containing unique extra certificates to cause memory exhaustion, eventually resulting in a denial of service.

Details

Affected packages:
openssl @ 3.2.2 (+3 more)

Fixes