Memory Pressure Vulnerability in OpenSSL Affects Multiple Versions
CVE-2026-35189

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-35189?

A vulnerability in OpenSSL allows targeted exploitation of certificate processing during TLS handshakes. Specifically, a crafted certificate containing numerous nameRelativeToCRLIssuer CRL distribution points can lead to excessive heap memory growth, resulting in significant memory pressure on both client and server systems. This condition may crash affected systems by exhausting memory resources, particularly when handling multiple concurrent connections. The vulnerability is mitigated by deferring the processing of CRL distribution points extensions until they are required, thus preventing prolonged high memory allocations.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.3

OpenSSL 3.6.0 < 3.6.5

OpenSSL 3.5.0 < 3.5.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fuzz0x (ZKSC Institute of Security Research)
Viktor Dukhovni
.