CVE-2026-14457
Received Received - Intake

NULL Pointer Dereference in OpenSSL with RFC7250 Raw Public Keys

Vulnerability report for CVE-2026-14457, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: OpenSSL Software Foundation

Description

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key. Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below. FIPS impact: no No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
openssl openssl 4.0
openssl openssl 3.6
openssl openssl 3.5
openssl openssl 3.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-14457 is a NULL pointer dereference vulnerability in OpenSSL affecting configurations using RFC7250 Raw Public Keys (RPKs) with only a private key configured. When a remote peer sends the 'signature_algorithms_cert' TLS extension, it may cause the application to crash due to improper handling.

Detection Guidance

This vulnerability affects systems using OpenSSL with RFC7250 Raw Public Keys (RPKs) configured with only a private key. Detection requires checking OpenSSL version and configuration. Use 'openssl version' to verify if your OpenSSL version is 4.0, 3.6, 3.5, or 3.4. If so, check if RPK-only configurations are in use by examining TLS server/client configurations for private key files without associated certificates.

Impact Analysis

The vulnerability can cause a Denial of Service by crashing the application. No data disclosure or remote command execution is possible. Systems using key-only RPK configurations without certificates are affected.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it only causes a Denial of Service (DoS) and does not lead to data disclosure or remote code execution. However, organizations using affected OpenSSL configurations must ensure they upgrade to patched versions to maintain secure systems required by these standards.

Mitigation Strategies

Upgrade OpenSSL to the latest patched version immediately. If RPK-only configurations are necessary, pair private keys with certificates to enable fallback to X.509 handshakes. Avoid using key-only RPK setups as they are uncommon and unsupported in best practices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14457. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart