Out-of-bounds Write Vulnerability in OpenSSL TLS Server
CVE-2026-72897
Currently unrated
What is CVE-2026-72897?
A vulnerability exists in OpenSSL where a TLS server mistakenly accesses memory beyond an internal array's bounds if it changes the SSL_CTX context during a handshake. This situation can occur when a server attempts to serve a different virtual host without updating its context correctly, potentially allowing a remote peer to initiate out-of-bounds reads or writes, which may disrupt service. This vulnerability primarily affects configurations that employ different provider signature algorithms between the original and replacement contexts, making misconfigurations especially critical to identify and address.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9