CVE-2026-84783
Received Received - Intake

Use-After-Free in OpenSSL 4.0 TLS Certificate Handling

Vulnerability report for CVE-2026-84783, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
openssl openssl to 4.0.3 (inc)
openssl openssl 3.6
openssl openssl 3.5
openssl openssl 3.4
openssl openssl 3.0
openssl openssl 1.1.1
openssl openssl 1.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a use-after-free issue in OpenSSL 4.0 where multiple threads concurrently access the same X.509 certificate. The first thread to decode the certificate's extensions caches them, but subsequent threads overwrite this cache while earlier threads may still be using the freed memory, leading to crashes.

Detection Guidance

This vulnerability affects only OpenSSL 4.0 versions before 4.0.3. To detect it, check your OpenSSL version with 'openssl version'. If you are running OpenSSL 4.0.0, 4.0.1, or 4.0.2, your system is vulnerable.

Impact Analysis

A remote attacker could exploit this to crash a multi-threaded TLS client or server, causing a Denial of Service. This affects systems using OpenSSL 4.0 that share trusted CA certificates across multiple connections.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by crashing multi-threaded TLS clients or servers through a use-after-free read. It does not directly impact data confidentiality, integrity, or privacy required by standards like GDPR or HIPAA. However, a DoS condition could disrupt services handling sensitive data, potentially leading to compliance violations if critical systems become unavailable.

Mitigation Strategies

Upgrade OpenSSL to version 4.0.3 or later immediately. Use your package manager to update (e.g., 'apt upgrade openssl' or 'yum update openssl'). If compiling from source, download and install OpenSSL 4.0.3 from the official OpenSSL website.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84783. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart