Memory leak in OpenSSL - CVE-2026-54876
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in OCSP response checking during X.509 certificate chain verification when processing a stapled OCSP response containing no single response entries. A remote attacker can send a malicious TLS server response to cause a denial of service.
Only client applications that explicitly enable OCSP response check verification flags are affected.