CVE-2026-75805
Received Received - Intake

NULL Pointer Dereference in OpenSSL CMP Client

Vulnerability report for CVE-2026-75805, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference issue in OpenSSL's Certificate Management Protocol (CMP) client. When a client requests certificate revocation using a PKCS#10 CSR instead of a certificate's issuer name and serial number, a malicious or compromised CMP server can send a crafted response. This causes the client to dereference a NULL pointer while comparing certificate details, leading to a crash and Denial of Service.

Detection Guidance

This vulnerability affects OpenSSL CMP clients using PKCS#10 CSR for certificate revocation. To detect it, check if your OpenSSL version is vulnerable by running: openssl version. If using a vulnerable version, monitor for crashes in CMP client applications during certificate revocation operations.

Impact Analysis

The impact is a Denial of Service for applications using OpenSSL's CMP client to revoke certificates via PKCS#10 CSR. The affected application will crash, disrupting services that rely on certificate revocation. Only clients using PKCS#10 CSR for revocation are vulnerable; those using issuer name and serial number are not affected.

Mitigation Strategies

Update OpenSSL to the latest patched version immediately. If updating is not possible, disable CMP client certificate revocation via PKCS#10 CSR by avoiding the 'openssl cmp -cmd rr -csr' command or OSSL_CMP_CTX_set1_p10CSR() API usage until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75805. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart