CVE-2026-28387
published 2026-04-07CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may…
PriorityP355high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.76%
51.1th percentile
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA records, may
result in a use-after-free and/or double-free on the client side.
Impact summary: A use after free can have a range of potential consequences
such as the corruption of valid data, crashes or execution of arbitrary code.
However, the issue only affects clients that make use of TLSA records with both
the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate
usage.
By far the most common deployment of DANE is in SMTP MTAs for which RFC7672
recommends that clients treat as 'unusable' any TLSA records that have the PKIX
certificate usages. These SMTP (or other similar) clients are not vulnerable
to this issue. Conversely, any clients that support only the PKIX usages, and
ignore the DANE-TA(2) usage are also not vulnerable.
The client would also need to be communicating with a server that publishes a
TLSA RRset with both types of TLSA records.
No FIPS modules are affected by this issue, the problem code is outside the
FIPS module boundary.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 3.0.19-1~deb12u2 (bookworm) | openssl 3.0.19-1~deb12u2 (bookworm) |
| msrc | azl3_openssl_3.3.5-4_on_azure_linux_3.0 | — | — |
| openssl | openssl | >= 0 < 3.5.6-r0 | 3.5.6-r0 |
| openssl | openssl | >= 0 < 3.5.6-r0 | 3.5.6-r0 |
| openssl | openssl | >= 0 < 3.0.19-1~deb12u2 | 3.0.19-1~deb12u2 |
| openssl | openssl | >= 0 < 3.5.5-1~deb13u2 | 3.5.5-1~deb13u2 |
| openssl | openssl | >= 1.1.1 < 1.1.1zg | 1.1.1zg |
| openssl | openssl | >= 3.0.0 < 3.0.20 | 3.0.20 |
| openssl | openssl | >= 3.3.0 < 3.3.7 | 3.3.7 |
| openssl | openssl | >= 3.4.0 < 3.4.5 | 3.4.5 |
| openssl | openssl | >= 3.5.0 < 3.5.6 | 3.5.6 |
| openssl | openssl | >= 3.6.0 < 3.6.2 | 3.6.2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.5HIGH
vendor_msrc3.8LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenSSL up to 3.6.1 DANE Client Code use after free (EUVD-2026-19961 / Nessus ID 305682)
vuldb·2026-05-02·CVSS 8.1
CVE-2026-28387 [HIGH] OpenSSL up to 3.6.1 DANE Client Code use after free (EUVD-2026-19961 / Nessus ID 305682)
A vulnerability categorized as critical has been discovered in OpenSSL up to 3.6.1. This affects an unknown function of the component DANE Client Code. The manipulation results in use after free.
This vulnerability is reported as CVE-2026-28387. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
GHSA-h2cc-wx97-xp8v: Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA recor
ghsa_unreviewed·2026-04-08
CVE-2026-28387 CWE-416 GHSA-h2cc-wx97-xp8v: Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA recor
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA records, may
result in a use-after-free and/or double-free on the client side.
Impact summary: A use after free can have a range of potential consequences
such as the corruption of valid data, crashes or execution of arbitrary code.
However, the issue only affects clients that make use of TLSA records with both
the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate
usage.
By far the most common deployment of DANE is in SMTP MTAs for which RFC7672
recommends that clients treat as 'unusable' any TLSA records that have the PKIX
certificate usages. These SMTP (or other similar) clients are not vulnerable
to this issue. Conversel
OSV
CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA recor
osv·2026-04-07
CVE-2026-28387 CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA recor
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA records, may
result in a use-after-free and/or double-free on the client side.
Impact summary: A use after free can have a range of potential consequences
such as the corruption of valid data, crashes or execution of arbitrary code.
However, the issue only affects clients that make use of TLSA records with both
the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate
usage.
By far the most common deployment of DANE is in SMTP MTAs for which RFC7672
recommends that clients treat as 'unusable' any TLSA records that have the PKIX
certificate usages. These SMTP (or other similar) clients are not vulnerable
to this issue. Conversel
OSV
CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA recor
osv·2026-04-07
CVE-2026-28387 CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA recor
Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely,
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2026-04-09·CVSS 7.5
CVE-2026-28387 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
USN-8155-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding updates for openssl and openssl1.0 packages for Ubuntu 14.04
LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
Viktor Dukhovni discovered that OpenSSL incorrectly negotiated the
expected preferred key exchange group when used as a TLS 1.3 server. This
could result in a less preferred key exchange being used, contrary to
expectations. This issue only affected Ubuntu 25.10. (CVE-2026-2673)
Igor Morgenstern discovered that OpenSSL incorrectly handled certain
memory operations when used as a DANE client. A remote attacker could use
this issue to cause OpenSSL to crash, resulting in
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2026-04-08·CVSS 7.5
CVE-2026-28388 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Viktor Dukhovni discovered that OpenSSL incorrectly negotiated the expected
preferred key exchange group when used as a TLS 1.3 server. This could
result in a less preferred key exchange being used, contrary to
expectations. This issue only affected Ubuntu 25.10. (CVE-2026-2673)
Igor Morgenstern discovered that OpenSSL incorrectly handled certain memory
operations when used as a DANE client. A remote attacker could use this
issue to cause OpenSSL to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-28387)
Igor Morgenstern discovered that OpenSSL incorrectly handled certain memory
operations when processing a delta CRL. A remote attacker could possibly
use this iss
Red Hat
openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
vendor_redhat·2026-04-07·CVSS 3.7
CVE-2026-28387 [LOW] CWE-1341 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
A flaw was found in OpenSSL. An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. This vulnerability could lead to data corruption, application crashes, or, in severe cases, arbitrary code execution. This issue is highly specific and uncommon, as it only affects clients using both PKIX-TA(0)/PKIX-EE(1) and DANE-TA(2) certificate usages and communicating with a server publishing a TLSA record set with both types of records.
Statement: This Low impact vulnerability affects clients performing DANE TLSA-based server authentication only when config
Microsoft
Potential Use-after-free in DANE Client Code
vendor_msrc·2026-04-02·CVSS 3.8
CVE-2026-28387 [LOW] CWE-416 Potential Use-after-free in DANE Client Code
Potential Use-after-free in DANE Client Code
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Debian
CVE-2026-28387: openssl - Issue summary: An uncommon configuration of clients performing DANE TLSA-based s...
vendor_debian·2026
CVE-2026-28387 CVE-2026-28387: openssl - Issue summary: An uncommon configuration of clients performing DANE TLSA-based s...
Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely,
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-28387 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
bugzilla·2026-03-25
CVE-2026-28387 [LOW] CVE-2026-28387 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
CVE-2026-28387 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA records, may
result in a use-after-free and/or double-free on the client side.
Impact summary: A use after free can have a range of potential consequences
such as the corruption of valid data, crashes or execution of arbitrary code.
However, the issue only affects clients that make use of TLSA records with both
the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate
usage.
By far the most common deployment of DANE is in SMTP MTAs for which RFC7672
recommends that clients treat as "unusable" any TLSA records that have t
Wiz
CVE-2026-28387 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-28387 CVE-2026-28387 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28387 :
OpenSSL vulnerability analysis and mitigation
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA records, may
result in a use-after-free and/or double-free on the client side.
Impact summary: A use after free can have a range of potential consequences
such as the corruption of valid data, crashes or execution of arbitrary code.
However, the issue only affects clients that make use of TLSA records with both
the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate
usage.
By far the most common deployment of DANE is in SMTP MTAs for which RFC7672
recommends that clients treat as 'unusable' any TLSA records that have the PKIX
certificate usages. These SMTP (o
Wiz
CVE-2026-5190 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-5190 [HIGH] CVE-2026-5190 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5190 :
Linux openSUSE vulnerability analysis and mitigation
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages.
To remediate this issue, users should upgrade to version 0.6.0 or later.
Source : NVD
## 7.7
Score
Published March 31, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
Linux openSUSE
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
aws-c-event-stream-devel
libaws-c-event-
https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012bhttps://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbehttps://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177https://openssl-library.org/news/secadv/20260407.txthttps://cert-portal.siemens.com/productcert/html/ssa-032379.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.html
2026-04-07
Published