TLS OCSP Stapling Vulnerability in OpenSSL
CVE-2026-35188

5MEDIUM

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
9 June 2026

What is CVE-2026-35188?

A flaw exists in the implementation of TLS OCSP stapling in OpenSSL, where a malicious server can exploit this vulnerability by sending a crafted OCSP response through the status_request extension. This exploitation could trigger a double-free error in the client's certificate verification sequence, leading to potential heap memory corruption. While the primary risk involves the possibility of a Denial of Service attack, reliable execution of arbitrary code through this method is complex and dependent on specific environmental factors. By default, OCSP stapling is not enabled, reducing its immediate exposure. This issue does not affect FIPS modules, as the vulnerable code lies outside the OpenSSL FIPS module boundary.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.1

OpenSSL 3.6.0 < 3.6.3

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wang Kenaz (University of Illinois)
Guido Vranken (Aisle Research)
Aaron Grattafiori (Nvidia)
Daniel Kubec
.