Allocation of Resources Without Limits or Throttling in OpenSSL - CVE-2026-63074
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in OpenSSL CMP extraCerts caching when processing rejected CMP messages containing additional certificates. A remote user can repeatedly send CMP requests with unique extra certificates to cause a denial of service.
The issue affects servers that reuse a single OSSL_CMP_CTX for the lifetime of the server process, allowing the untrusted certificate stack to grow without being expunged after message rejection.
Affected software
Debian Linux
FreeBSD
openssl (Debian package)
How to mitigate CVE-2026-63074
openssl (Debian package) - update to 3.5.7-1~deb13u2