Intel

AIKIDO-2026-240636

openssl is vulnerable to Memory Leak

Memory LeakCVE-2026-54876 Published 6 days ago

37

Low Risk

This Affects:

C++openssl
3.6.0 - 3.6.3
Fixed in 3.6.4
4.0.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

When OCSP response checking is enabled, a Basic OCSP response with an empty list of single responses returns early and skips freeing the OCSP_BASICRESP structure. A TLS server can repeat that response, and can pad it with extra certificates, so a long running client leaks memory on each handshake until it runs out of memory. The fix frees the response structure when the single response list is empty.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your TLS client enables OCSP response checking.

Background info

openssl is vulnerable to Memory Leak in versions 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.

How to fix this

Upgrade the openssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform