CVE-2026-35189
Received Received - Intake

Heap Exhaustion in OpenSSL via CRL Distribution Points

Vulnerability report for CVE-2026-35189, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a certificate with many nameRelativeToCRLIssuer CRL distribution points causing excessive heap memory growth during OpenSSL's processing of X.509 extensions. This leads to significant memory usage and potential Denial of Service in clients or servers requesting client certificates.

Detection Guidance

This vulnerability is related to OpenSSL's handling of certificates with many CRL distribution points. Detection involves checking OpenSSL versions and monitoring memory usage during TLS handshakes. Use 'openssl version' to check the installed version. If vulnerable, update OpenSSL immediately. Monitor system memory during TLS connections with tools like 'top' or 'htop' to detect abnormal memory spikes during certificate parsing.

Impact Analysis

A malicious peer could send a crafted certificate that causes your system to allocate several hundred MiB of memory during a TLS handshake. This may crash your application or system if multiple such connections occur simultaneously, leading to service disruption.

Compliance Impact

This vulnerability primarily causes Denial of Service (DoS) conditions due to excessive memory consumption during TLS handshakes. It does not directly impact data privacy or security controls required by standards like GDPR or HIPAA. However, prolonged DoS conditions could indirectly affect compliance by disrupting availability of systems handling personal or health data.

Mitigation Strategies

Update OpenSSL to the latest patched version to address the heap growth issue caused by CRL distribution points in certificates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-35189. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart