Double free in OpenSSL - CVE-2026-35188
Published: June 10, 2026
OpenSSL
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to double free in the client's certificate verification path when checking a crafted OCSP stapled response delivered through the status_request extension. A remote attacker can deliver a crafted OCSP stapled response to cause a denial of service.
OCSP stapling is not enabled by default.