Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyAgreeRecipientInfo a NULL pointer dereference can happen.
Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial of Service.
When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is
processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier
is examined without checking for its presence. This results in a NULL
pointer dereference if the field is missing.
Applications and services that call CMS_decrypt() on untrusted input
(e.g., S/MIME processing or CMS-based protocols) are vulnerable.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.
References
Configurations
Configuration 1 (hide)
|
History
12 May 2026, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Apr 2026, 15:40
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | |
| First Time |
Openssl openssl
Openssl |
|
| References | () https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5 - Patch | |
| References | () https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616 - Patch | |
| References | () https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f - Patch | |
| References | () https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a - Patch | |
| References | () https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686 - Patch | |
| References | () https://openssl-library.org/news/secadv/20260407.txt - Vendor Advisory |
10 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
07 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-07 22:16
Updated : 2026-05-12 13:17
NVD link : CVE-2026-28389
Mitre link : CVE-2026-28389
CVE.ORG link : CVE-2026-28389
JSON object : View
Products Affected
openssl
- openssl
CWE
CWE-476
NULL Pointer Dereference
