Asymmetric Resource Consumption Vulnerability in OpenSSL DTLS
CVE-2026-54874
Currently unrated
What is CVE-2026-54874?
OpenSSL's DTLS implementation suffers from a resource consumption issue, whereby an attacker can exploit the protocol's buffering mechanism during a handshake. By sending a series of small forged records, the adversary causes the OpenSSL DTLS endpoint to retain excessive memory. This vulnerability enables a significant memory amplification effect, with the potential to exhaust memory resources on the affected server, leading to Denial of Service. Users are advised to upgrade to the patched versions of OpenSSL to mitigate this risk.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.2
OpenSSL 3.6.0 < 3.6.4
OpenSSL 3.5.0 < 3.5.8