DIRAS TAKE
Urgent: apply vendor updates or mitigations since an attacker controlling or intercepting a CMP endpoint can trigger a crash without authentication.
What is CVE-2026-63073?
A remote attacker who can act as or intercept a CMP endpoint can crash OpenSSL CMP clients, causing a denial of service (CVE-2026-63073). The flaw is a format-string vulnerability in CMP response validation that lets an attacker-controlled sender distinguished name be used as a format string. Affected releases are 4.0.0 through before 4.0.2, 3.6.0 through before 3.6.4, 3.5.0 through before 3.5.8, and 3.4.0 through before 3.4.7; exploitation requires network access to a CMP endpoint and does not require prior authentication.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of OpenSSL OpenSSL are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 4.x | 4.0.0 – before 4.0.2 | 4.0.2 |
| 3.x | 3.6.0 – before 3.6.4 | 3.6.4 |
| 3.x | 3.5.0 – before 3.5.8 | 3.5.8 |
| 3.x | 3.4.0 – before 3.4.7 | 3.4.7 |
Is CVE-2026-63073 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-63073
- Upgrade OpenSSL to 4.0.2 if using 4.x releases.
- Upgrade OpenSSL to 3.6.4, 3.5.8, or 3.4.7 for the respective 3.x branches.
- Restrict network exposure to CMP endpoints and limit which peers can connect.
- Monitor CMP client logs and crash reports for unexpected failures and apply vendor guidance.
Frequently asked questions
Is CVE-2026-63073 being actively exploited?
There are no public reports of active exploitation of CVE-2026-63073 as of 2026-09-29.
Which OpenSSL versions are affected by CVE-2026-63073?
OpenSSL CMP implementations in 4.0.0 through before 4.0.2, 3.6.0 through before 3.6.4, 3.5.0 through before 3.5.8, and 3.4.0 through before 3.4.7 are affected.
Is there a patch for CVE-2026-63073?
Yes; OpenSSL provides fixes in versions 4.0.2, 3.6.4, 3.5.8, and 3.4.7.
Does CVE-2026-63073 require authentication?
No; exploitation does not require authentication and can occur when an attacker controls or intercepts the CMP endpoint.
References
- nvd.nist.gov/vuln/detail/CVE-2026-63073
- cve.org/CVERecord?id=CVE-2026-63073
- openssl-library.org/news/secadv/20260825.txt
- github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21
- github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29
- github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca
- github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4
- All OpenSSL CVEs on CVE Radar
- CVEs published in September 2026