Memory Leak Vulnerability in OpenSSL Affected by Malicious TLS Certificates
CVE-2026-54876

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-54876?

A vulnerability in OpenSSL arises from improper handling of OCSP responses during TLS handshakes. When an attacker sends a malformed OCSP response with no single response entries, it causes a memory leak in the client, particularly when OCSP response checking is enabled. This could lead to substantial memory exhaustion in applications that establish repeated connections with malicious servers, posing a risk of Denial of Service. The issue is particularly relevant for client applications that enable OCSP response verification, as the OpenSSL decoder accepts empty responses, leading to unforeseen memory retention.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.2

OpenSSL 3.6.0 < 3.6.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bhabani Sankar Das
Zhenzhe Shao
Mounir Idrassi
.