THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-63076 (HIGH 7.5) — Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced a

[NVD] CVE-2026-63076 (HIGH 7.5) — Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced a

mednvdPublished 2026-08-25

CVE-2026-63076 CVSS: 7.5 HIGH Published: 2026-08-25T13:19:26.543

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.

Impact summary: A remote, unaut

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63076