Asymmetric Resource Consumption Vulnerability in OpenSSL DTLS
CVE-2026-54874

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-54874?

OpenSSL's DTLS implementation suffers from a resource consumption issue, whereby an attacker can exploit the protocol's buffering mechanism during a handshake. By sending a series of small forged records, the adversary causes the OpenSSL DTLS endpoint to retain excessive memory. This vulnerability enables a significant memory amplification effect, with the potential to exhaust memory resources on the affected server, leading to Denial of Service. Users are advised to upgrade to the patched versions of OpenSSL to mitigate this risk.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.2

OpenSSL 3.6.0 < 3.6.4

OpenSSL 3.5.0 < 3.5.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amazon Web Services
Matt Caswell
.