Memory Leak Vulnerability in OpenSSL Affected by Malicious TLS Certificates
CVE-2026-54876
Currently unrated
What is CVE-2026-54876?
A vulnerability in OpenSSL arises from improper handling of OCSP responses during TLS handshakes. When an attacker sends a malformed OCSP response with no single response entries, it causes a memory leak in the client, particularly when OCSP response checking is enabled. This could lead to substantial memory exhaustion in applications that establish repeated connections with malicious servers, posing a risk of Denial of Service. The issue is particularly relevant for client applications that enable OCSP response verification, as the OpenSSL decoder accepts empty responses, leading to unforeseen memory retention.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.2
OpenSSL 3.6.0 < 3.6.4