THREAT OPS › Threat News › [NVD] CVE-2026-63074 (MEDIUM 5.9) — Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
additional certificates (extraCerts) sent in a CMP message, but never expunges
them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX
frequently, this cache of extraCerts may grow unboun
[NVD] CVE-2026-63074 (MEDIUM 5.9) — Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboun
CVE-2026-63074 CVSS: 5.9 MEDIUM Published: 2026-08-25T13:19:26.283
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server
Indicators of compromise
- CVE-2026-63074cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63074