OpenSSL CMP Remote Denial of Service Vulnerability in Multiple Versions
CVE-2026-63076
Currently unrated
What is CVE-2026-63076?
This vulnerability in the OpenSSL library affects its capability to securely verify password-based message authentication codes in CMP messages. An improper validation of the protection algorithm parameter during the verification process allows a malicious actor to craft a malicious message that can lead to a denial of service. Specifically, when handling PBM-protected messages, the library checks that the protection algorithm pointer is not NULL without verifying its ASN.1 type. This oversight can be exploited by remote, unauthenticated attackers, resulting in the crashing of applications serving as CMP servers or clients interacting with compromised servers.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.2
OpenSSL 3.6.0 < 3.6.4
OpenSSL 3.5.0 < 3.5.8