OpenSSL CMP Remote Denial of Service Vulnerability in Multiple Versions
CVE-2026-63076

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-63076?

This vulnerability in the OpenSSL library affects its capability to securely verify password-based message authentication codes in CMP messages. An improper validation of the protection algorithm parameter during the verification process allows a malicious actor to craft a malicious message that can lead to a denial of service. Specifically, when handling PBM-protected messages, the library checks that the protection algorithm pointer is not NULL without verifying its ASN.1 type. This oversight can be exploited by remote, unauthenticated attackers, resulting in the crashing of applications serving as CMP servers or clients interacting with compromised servers.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.2

OpenSSL 3.6.0 < 3.6.4

OpenSSL 3.5.0 < 3.5.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ying Dong
Bhabani Sankar Das
Daniel Kubec
.