CVE-2026-35188
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.
Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.
If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.
Leer descripción completaMostrar menos
The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.
No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-415
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-35188",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-35188",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-06-10T03:59:37.106557Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "openssl-security@openssl.org",
"affectedData": [
{
"vendor": "OpenSSL",
"product": "OpenSSL",
"versions": [
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.0.1",
"versionType": "semver"
},
{
"status": "affected",
"version": "3.6.0",
"lessThan": "3.6.3",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-09T17:17:05.437",
"references": [
{
"url": "https://github.com/openssl/openssl/commit/131145d25659e8749a9ed1afb383484854cffb78",
"tags": [
"Patch"
],
"source": "openssl-security@openssl.org"
},
{
"url": "https://github.com/openssl/openssl/commit/78d0154cffda03aaaac63a087cc523a6b35fa8fd",
"tags": [
"Patch"
],
"source": "openssl-security@openssl.org"
},
{
"url": "https://openssl-library.org/news/secadv/20260609.txt",
"tags": [
"Vendor Advisory"
],
"source": "openssl-security@openssl.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "openssl-security@openssl.org",
"description": [
{
"lang": "en",
"value": "CWE-415"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering\na crafted response through the status_request extension, triggering a\ndouble-free in the client's certificate verification path.\n\nImpact summary: Successful exploitation allows an attacker to corrupt heap\nmemory via a double-free, potentially leading to a Denial of Service or\npossibly an attacker controlled code execution or other undefined behavior.\n\nIf OCSP stapling is enabled and the TLS client connects to a malicious server,\na crafted OCSP stapled response can trigger a double free in the TLS client\nwhen the stapled response is checked.\n\nThe OCSP stapling is not enabled by default. Reliable code execution\nthrough a double-free is technically complex and highly environment-dependent\nbut the Denial of Service impact is straightforward to achieve, warranting\nModerate severity.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."
},
{
"lang": "es",
"value": "Resumen del problema: Un servidor malicioso puede explotar el 'TLS OCSP stapling' entregando una respuesta manipulada a través de la 'extension status_request', desencadenando un 'double-free' en la ruta de verificación de certificados del cliente.\n\nResumen del impacto: La explotación exitosa permite a un atacante corromper la memoria 'heap' a través de un 'double-free', lo que podría llevar a una denegación de servicio o posiblemente a una ejecución de código controlada por el atacante u otro comportamiento indefinido.\n\nSi el 'OCSP stapling' está habilitado y el cliente TLS se conecta a un servidor malicioso, una respuesta 'OCSP stapled' manipulada puede desencadenar un 'double free' en el cliente TLS cuando se verifica la respuesta 'stapled'.\n\nEl 'OCSP stapling' no está habilitado por defecto. La ejecución de código fiable a través de un 'double-free' es técnicamente compleja y altamente dependiente del entorno, pero el impacto de denegación de servicio es sencillo de lograr, lo que justifica una severidad Moderada.\n\nNingún módulo FIPS se ve afectado por este problema, ya que el código afectado está fuera del límite del módulo FIPS de OpenSSL."
}
],
"lastModified": "2026-07-23T08:10:00.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D41B3C45-EC73-4DC8-989D-B2E2792E102F",
"versionEndExcluding": "3.6.3",
"versionStartIncluding": "3.6.0"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E881B9A-1A0A-4BC0-8160-20C00561167D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "openssl-security@openssl.org"
}