PT-2026-47833 · Openssl · Openssl

·

CVE-2026-35188

·

Published

2026-06-09

·

Updated

2026-07-15

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status request extension. This triggers a double-free in the client's certificate verification path when the stapled response is checked. A double-free occurs when a program attempts to free the same memory location twice, which can corrupt heap memory. This may lead to a Denial of Service, attacker-controlled code execution, or other undefined behavior. OCSP stapling is not enabled by default.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling OCSP stapling to minimize the risk of exploitation.

Exploit

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35188
ZDI-26-425

Affected Products

Openssl