Intel

AIKIDO-2026-590576

openssl is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-63074 Published 6 days ago

37

Low Risk

This Affects:

C++openssl
3.0.0 - 3.0.21
Fixed in 3.0.22
3.4.0 - 3.4.6
Fixed in 3.4.7
3.5.0 - 3.5.7
Fixed in 3.5.8
3.6.0 - 3.6.3
Fixed in 3.6.4
4.0.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

A CMP server that reuses one OSSL_CMP_CTX keeps extra certificates from incoming messages in that context after the message is rejected. A client can repeat rejected messages that each carry a new set of extra certificates, and the cache grows without a limit until the process runs out of memory. The fix drops those extra certificates when the message is rejected.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your CMP server reuses one OSSL_CMP_CTX across requests.

Background info

openssl is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 3.0.21, 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.

How to fix this

Upgrade the openssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform