THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-63074 (MEDIUM 5.9) — Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboun

[NVD] CVE-2026-63074 (MEDIUM 5.9) — Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboun

mednvdPublished 2026-08-25

CVE-2026-63074 CVSS: 5.9 MEDIUM Published: 2026-08-25T13:19:26.283

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63074