cbcvebase.
CVE-2026-28390
published 2026-04-07

CVE-2026-28390: Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.80%
52.7th percentile
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianopenssl< openssl 3.0.19-1~deb12u2 (bookworm)openssl 3.0.19-1~deb12u2 (bookworm)
opensslopenssl>= 0 < 3.5.6-r03.5.6-r0
opensslopenssl>= 0 < 3.5.6-r03.5.6-r0
opensslopenssl>= 0 < 3.0.19-1~deb12u23.0.19-1~deb12u2
opensslopenssl>= 0 < 3.5.5-1~deb13u23.5.5-1~deb13u2
opensslopenssl>= 1.0.2 < 1.0.2zp1.0.2zp
opensslopenssl>= 1.1.1 < 1.1.1zg1.1.1zg
opensslopenssl>= 3.0.0 < 3.0.203.0.20
opensslopenssl>= 3.3.0 < 3.3.73.3.7
opensslopenssl>= 3.4.0 < 3.4.53.4.5
opensslopenssl>= 3.5.0 < 3.5.63.5.6
opensslopenssl>= 3.6.0 < 3.6.23.6.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.