Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR...

zetlyn/cve-ghsa vulnerability ghsa GHSA-gpg3-m652-f2vc cve CVE-2026-75805 known 2026-09-29

https://github.com/advisories/GHSA-gpg3-m652-f2vc

Properties

cvss5.3
receipt
Source
GitHub advisories
Its words
5.3
Read by
field:cvss.score
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-75805",
  "cvss": {
    "score": 5.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-476",
      "name": "NULL Pointer Dereference"
    }
  ],
  "description": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
  "epss": {
    "percentage": 0.00222,
    "percentile": 0.11535
  },
  "ghsa_id": "GHSA-gpg3-m652-f2vc",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gpg3-m652-f2vc",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gpg3-m652-f2vc"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-75805"
    }
  ],
  "nvd_published_at": "2026-09-29T16:17:11Z",
  "published_at": "2026-09-29T18:31:44Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-75805",
    "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166",
    "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7",
    "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3",
    "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f",
    "https://openssl-library.org/news/secadv/20260929.txt",
    "https://github.com/advisories/GHSA-gpg3-m652-f2vc"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T18:31:49Z",
  "url": "https://api.github.com/advisories/GHSA-gpg3-m652-f2vc",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-476
receipt
Source
GitHub advisories
Its words
CWE-476
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-75805",
  "cvss": {
    "score": 5.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-476",
      "name": "NULL Pointer Dereference"
    }
  ],
  "description": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
  "epss": {
    "percentage": 0.00222,
    "percentile": 0.11535
  },
  "ghsa_id": "GHSA-gpg3-m652-f2vc",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gpg3-m652-f2vc",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gpg3-m652-f2vc"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-75805"
    }
  ],
  "nvd_published_at": "2026-09-29T16:17:11Z",
  "published_at": "2026-09-29T18:31:44Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-75805",
    "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166",
    "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7",
    "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3",
    "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f",
    "https://openssl-library.org/news/secadv/20260929.txt",
    "https://github.com/advisories/GHSA-gpg3-m652-f2vc"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T18:31:49Z",
  "url": "https://api.github.com/advisories/GHSA-gpg3-m652-f2vc",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitymedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-75805",
  "cvss": {
    "score": 5.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-476",
      "name": "NULL Pointer Dereference"
    }
  ],
  "description": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
  "epss": {
    "percentage": 0.00222,
    "percentile": 0.11535
  },
  "ghsa_id": "GHSA-gpg3-m652-f2vc",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gpg3-m652-f2vc",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gpg3-m652-f2vc"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-75805"
    }
  ],
  "nvd_published_at": "2026-09-29T16:17:11Z",
  "published_at": "2026-09-29T18:31:44Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-75805",
    "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166",
    "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7",
    "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3",
    "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f",
    "https://openssl-library.org/news/secadv/20260929.txt",
    "https://github.com/advisories/GHSA-gpg3-m652-f2vc"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR...",
  "type": "unreviewed",
  "updated_at": "2026-09-29T18:31:49Z",
  "url": "https://api.github.com/advisories/GHSA-gpg3-m652-f2vc",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR... Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.