CVE-2026-28387Use After Free in Openssl

Severity
7.5HIGH
No vector
EPSS
0.0%
top 94.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 7
Latest updateApr 9

Description

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usa

Affected Packages5 packages

debiandebian/openssl< openssl 3.0.19-1~deb12u2 (bookworm)
CVEListV5openssl/openssl3.6.03.6.2+5
Alpineopenssl/openssl< 3.5.6-r0+1
Debianopenssl/openssl< 3.0.19-1~deb12u2+1

🔴Vulnerability Details

3
GHSA
GHSA-h2cc-wx97-xp8v: Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA recor2026-04-08
OSV
CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA recor2026-04-07
OSV
CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA recor2026-04-07

📋Vendor Advisories

5
Ubuntu
OpenSSL vulnerabilities2026-04-09
Ubuntu
OpenSSL vulnerabilities2026-04-08
Red Hat
openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication2026-04-07
Microsoft
Potential Use-after-free in DANE Client Code2026-04-02
Debian
CVE-2026-28387: openssl - Issue summary: An uncommon configuration of clients performing DANE TLSA-based s...2026

🕵️Threat Intelligence

2
Wiz
CVE-2026-28387 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-5190 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-28387 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication2026-03-25
CVE-2026-28387 — Use After Free in Openssl | cvebase