Use-after-free in OpenSSL - CVE-2026-84783
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in the X.509 extension cache when several threads first decode extensions for the same shared certificate. A remote attacker can cause concurrent certificate-chain construction to cause a denial of service.
The affected certificate must be a trusted CA certificate shared between connections.