Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-35189— Excessive Memory Allocation in Relative CRLDP Processing

Quick assessment

Affected
OpenSSL OpenSSL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memor

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-35189

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Excessive Memory Allocation in Relative CRLDP Processing
Source: CVE Program / CVE List V5
Vulnerability Description
Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenSSL OpenSSL 4.0.0 ~ 4.0.3 -

II. Public POCs for CVE-2026-35189

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-35189

请登录查看更多情报信息。

Other References for CVE-2026-35189 (5)

Same Patch Batch · OpenSSL · 2026-09-29 · 14 CVEs total

CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted
CVE-2026-75806 Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
CVE-2026-75804 QUIC Connection-Level Flow Control is Not Enforced for Streams
CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling
CVE-2026-42772 Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
CVE-2026-54873 QUIC STREAM Fragment Metadata DoS
CVE-2026-54872 Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
CVE-2026-77696 Timing Side-Channel in SM2 Signature Generation
CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
CVE-2026-84782 DTLS Retransmits Handshake Messages From a Stale Buffer Offset
CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use

IV. Related Vulnerabilities

V. Comments for CVE-2026-35189

No comments yet


Leave a comment