Format String Vulnerability in OpenSSL CMP Client
CVE-2026-63073

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-63073?

The OpenSSL CMP client has a flaw in its message validation process where peer-supplied sender distinguished names can be improperly passed as format strings. This occurs in scenarios where the client expects a specific sender or uses a pinned server certificate. If an attacker intercepts or injects a malicious CMP response, the client may experience a crash due to malicious format strings leading to a denial of service. This vulnerability does not allow for unauthorized memory access or code execution, but it effectively disrupts the service operations of the affected client.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.2

OpenSSL 3.6.0 < 3.6.4

OpenSSL 3.5.0 < 3.5.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Filipe Casal (Trail of Bits)
Brandon Luo
TrendAI Zero Day Initiative
Filipe Casal (Trail of Bits)
.