Null Pointer Dereference Vulnerability in OpenSSL CMP Client Application
CVE-2026-42767

5.9MEDIUM

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
9 June 2026

What is CVE-2026-42767?

The OpenSSL CMP client is susceptible to a NULL pointer dereference vulnerability, which can occur when processing a specially crafted response from an attacker-controlled Certificate Management Protocol (CMP) server. This vulnerability can lead to a crash of the CMP client application, thus resulting in a Denial of Service. An attacker could exploit this by sending a crafted CMP response that contains an improperly formatted CertRepMessage. It is crucial for users of affected versions of OpenSSL to apply the patches provided in recent updates to mitigate this security risk. Notably, FIPS modules in versions 4.0, 3.6, 3.5, 3.4, and 3.0 are not impacted by this issue.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.1

OpenSSL 3.6.0 < 3.6.3

OpenSSL 3.5.0 < 3.5.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhanpeng Liu (Tencent Xuanwu Lab)
Guannan Wang (Tencent Xuanwu Lab)
Guancheng Li (Tencent Xuanwu Lab)
Igor Ustinov
Tomáš Mráz
.