• PATCH AVAILABLE

CVE-2026-63073: format-string denial of service in OpenSSL OpenSSL

A remote attacker who can act as or intercept a CMP endpoint can crash OpenSSL CMP clients, causing a denial of service (CVE-2026-63073). The flaw is a format-string vulnerability in CMP response validation that lets an attacker-controlled sender distinguished name be used as a format string. Affected releases are 4.0.0 through before 4.0.2, 3.6.0 through before 3.6.4, 3.5.0 through before 3.5.8, and 3.4.0 through before 3.4.7; exploitation requires network access to a CMP endpoint and does not require prior authentication.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.01159
CWE
CWE-134
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: apply vendor updates or mitigations since an attacker controlling or intercepting a CMP endpoint can trigger a crash without authentication.

What is CVE-2026-63073?

A remote attacker who can act as or intercept a CMP endpoint can crash OpenSSL CMP clients, causing a denial of service (CVE-2026-63073). The flaw is a format-string vulnerability in CMP response validation that lets an attacker-controlled sender distinguished name be used as a format string. Affected releases are 4.0.0 through before 4.0.2, 3.6.0 through before 3.6.4, 3.5.0 through before 3.5.8, and 3.4.0 through before 3.4.7; exploitation requires network access to a CMP endpoint and does not require prior authentication.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of OpenSSL OpenSSL are affected?

BRANCHAFFECTEDFIXED
4.x4.0.0 – before 4.0.24.0.2
3.x3.6.0 – before 3.6.43.6.4
3.x3.5.0 – before 3.5.83.5.8
3.x3.4.0 – before 3.4.73.4.7

Is CVE-2026-63073 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-63073

  1. Upgrade OpenSSL to 4.0.2 if using 4.x releases.
  2. Upgrade OpenSSL to 3.6.4, 3.5.8, or 3.4.7 for the respective 3.x branches.
  3. Restrict network exposure to CMP endpoints and limit which peers can connect.
  4. Monitor CMP client logs and crash reports for unexpected failures and apply vendor guidance.

Frequently asked questions

Is CVE-2026-63073 being actively exploited?

There are no public reports of active exploitation of CVE-2026-63073 as of 2026-09-29.

Which OpenSSL versions are affected by CVE-2026-63073?

OpenSSL CMP implementations in 4.0.0 through before 4.0.2, 3.6.0 through before 3.6.4, 3.5.0 through before 3.5.8, and 3.4.0 through before 3.4.7 are affected.

Is there a patch for CVE-2026-63073?

Yes; OpenSSL provides fixes in versions 4.0.2, 3.6.4, 3.5.8, and 3.4.7.

Does CVE-2026-63073 require authentication?

No; exploitation does not require authentication and can occur when an attacker controls or intercepts the CMP endpoint.

References