Certificate Revocation Vulnerability in OpenSSL CMP Client
CVE-2026-75805

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-75805?

A vulnerability exists in the OpenSSL CMP client when a certificate revocation request is made using a PKCS#10 CSR. If the client receives a specially crafted response from a malicious or compromised server, it may attempt to read from a NULL pointer, resulting in an abnormal termination of the application. This situation can lead to a Denial of Service to the affected client, as it can’t properly process legitimate revocation responses. This issue does not affect clients that identify certificates to be revoked through issuer names or serial numbers.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.3

OpenSSL 3.6.0 < 3.6.5

OpenSSL 3.5.0 < 3.5.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bhabani Sankar Das
Bhabani Sankar Das
Norbert Pocs
.