Unbounded Memory Growth in OpenSSL CMP due to Improper Certificate Handling
CVE-2026-63074

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-63074?

The OpenSSL Certificate Management Protocol (CMP) improperly caches additional certificates in a server context, leading to potential Denial of Service. If a malicious client continuously sends requests with unique extra certificates, the server could experience unbounded memory growth. This unregulated caching can cause the server to become unresponsive, especially if the context (OSSL_CMP_CTX) is reused over time. The vulnerability poses a severe risk to servers that manage CMP requests without addressing this caching issue, as untrusted certificates persist indefinitely after rejected messages.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.2

OpenSSL 3.6.0 < 3.6.4

OpenSSL 3.5.0 < 3.5.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavоl Žáčik (Red Hat)
Neil Horman
.