Potential Subgroup Membership Issue in OpenSSL's DHX Key Derivation
CVE-2026-42770

3.7LOW

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
9 June 2026

What is CVE-2026-42770?

A vulnerability exists in OpenSSL when using the EVP_PKEY_derive_set_peer() function with DHX (X9.42) peer keys. The system fails to properly verify subgroup membership, which can be exploited by a malicious actor presenting a forged key. This leads to the potential exposure of a victim's private key after a limited series of key exchange attempts. The attack hinges on using domain parameters that match those of the victim, thus bypassing essential checks that would normally prevent unauthorized key recovery. The risk is primarily associated with CMP deployments and specialized applications employing long-lived DHX keys.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.1

OpenSSL 3.6.0 < 3.6.3

OpenSSL 3.5.0 < 3.5.7

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Gaynor (Anthropic)
Alex Gaynor (Anthropic)
Viktor Dukhovni
Norbert PĂłcs
.