PT-2026-47841 · Openssl · Openssl

·

CVE-2026-42771

·

Published

2026-06-09

·

Updated

2026-07-15

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description An out-of-bounds read occurs when an application calls the X509 VERIFY PARAM set1 email function to validate a crafted email address, such as during S/MIME message validation. This issue stems from an internal helper function called by X509 VERIFY PARAM set1 email() and X509 VERIFY PARAM add email() that uses an incorrect length when validating the local part of an email address. Consequently, the 64-octet limit for the local part may not be enforced, potentially leading to a crash and Denial of Service. The flaw is reachable via S-MIME validation using a crafted From: address in an email message.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42771
ZDI-26-426

Affected Products

Openssl