TLS OCSP Stapling Vulnerability in OpenSSL
CVE-2026-35188
What is CVE-2026-35188?
A flaw exists in the implementation of TLS OCSP stapling in OpenSSL, where a malicious server can exploit this vulnerability by sending a crafted OCSP response through the status_request extension. This exploitation could trigger a double-free error in the client's certificate verification sequence, leading to potential heap memory corruption. While the primary risk involves the possibility of a Denial of Service attack, reliable execution of arbitrary code through this method is complex and dependent on specific environmental factors. By default, OCSP stapling is not enabled, reducing its immediate exposure. This issue does not affect FIPS modules, as the vulnerable code lies outside the OpenSSL FIPS module boundary.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.1
OpenSSL 3.6.0 < 3.6.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved