Use After Free Vulnerability in OpenSSL 4.0 by OpenSSL
CVE-2026-84783

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-84783?

OpenSSL 4.0 is affected by a vulnerability that arises from concurrent access to the same X.509 certificate by multiple threads. This results in the risk of cached extension data being freed while still in use, leading to a potential Denial of Service. When first attempting to utilize an extension of a shared certificate, if multiple threads perform operations at the same time, they can inadvertently free memory still being accessed by others. This vulnerability primarily impacts multi-threaded TLS clients and servers that request client certificates, especially when utilizing the same trusted CA certificates across simultaneous connections.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tim Becker (Xint.io)
aydinmercan
Bob Beck
.