{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-75805","assignerOrgId":"3a12439a-ef3a-4c79-92e6-6081a721f1e5","state":"PUBLISHED","assignerShortName":"openssl","dateReserved":"2026-08-18T09:34:32.659Z","datePublished":"2026-09-29T15:32:20.408Z","dateUpdated":"2026-09-29T16:54:39.263Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"OpenSSL","vendor":"OpenSSL","versions":[{"lessThan":"4.0.3","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"3.6.5","status":"affected","version":"3.6.0","versionType":"semver"},{"lessThan":"3.5.9","status":"affected","version":"3.5.0","versionType":"semver"},{"lessThan":"3.4.8","status":"affected","version":"3.4.0","versionType":"semver"},{"lessThan":"3.0.23","status":"affected","version":"3.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Bhabani Sankar Das"},{"lang":"en","type":"remediation developer","value":"Bhabani Sankar Das"},{"lang":"en","type":"remediation developer","value":"Norbert Pocs"}],"datePublic":"2026-09-29T14:21:57.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Issue summary: A CMP client that requests certificate revocation on the basis<br>of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when<br>processing a crafted revocation response. <br><br>Impact summary: The NULL pointer dereference happens on a read which <br>leads to a crash and a Denial of Service for the affected client application.<br><br>CWE: CWE-476: NULL-pointer dereference<br><br>Description: A CMP client revoking a certificate has to tell the server which<br>certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the<br>certificate itself or its issuer name and serial number. This is<br>'openssl cmp -cmd rr -csr <file>' on the command line, or<br>OSSL_CMP_exec_RR_ses() with the certificate supplied via<br>OSSL_CMP_CTX_set1_p10CSR() through the API.<br><br>A CSR does not contain the issuer name and serial number of the certificate,<br>so the client does not send them. A server may optionally name the<br>certificate it revoked in its response, and the client then compares that<br>name against what it sent. Having sent neither an issuer name nor a serial<br>number, it has nothing to compare against, and a server returning a specially<br>crafted name causes the client to read from a NULL pointer and crash.<br><br>The revocation response is checked for valid message protection before<br>the affected code is reached, so an attacker must be a malicious or<br>compromised CMP server, or a man-in-the-middle in possession of the<br>secret used for message protection. Clients that identify the certificate<br>to be revoked by a certificate or by issuer and serial number rather<br>than by a PKCS#10 CSR are not affected.<br><br>FIPS impact: no<br>No FIPS modules are affected by this issue, as the CMP protocol<br>implementation is outside the OpenSSL FIPS module boundary."}],"value":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}],"metrics":[{"format":"other","other":{"content":{"text":"Low"},"type":"https://openssl-library.org/policies/general/security-policy/"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-476","description":"CWE-476 NULL-pointer dereference","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"3a12439a-ef3a-4c79-92e6-6081a721f1e5","shortName":"openssl","dateUpdated":"2026-09-29T15:32:20.408Z"},"references":[{"name":"OpenSSL Advisory","tags":["vendor-advisory"],"url":"https://openssl-library.org/news/secadv/20260929.txt"},{"name":"4.0.3 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7"},{"name":"3.6.5 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166"},{"name":"3.5.9 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3"},{"name":"3.4.8 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f"}],"source":{"discovery":"UNKNOWN"},"title":"NULL Pointer Dereference in CMP Client Revocation Response Handling","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.3,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"LOW","privilegesRequired":"NONE","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-09-29T16:54:03.315064Z","id":"CVE-2026-75805","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-29T16:54:39.263Z"}}]}}