{"id":"CVE-2026-28389","title":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentica…","summary":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentica…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"openssl","product":"openssl","affected":["openssl >= 1.0.2, < 1.0.2zp","openssl >= 1.1.1, < 1.1.1zg","openssl >= 3.0.0, < 3.0.20","openssl >= 3.3.0, < 3.3.7","openssl >= 3.4.0, < 3.4.5","openssl >= 3.5.0, < 3.5.6","openssl >= 3.6.0, < 3.6.2"],"patched":["openssl 3.6.2"],"published":"2026-04-07","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","references":[{"url":"https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","label":"openssl-security@openssl.org"},{"url":"https://openssl-library.org/news/secadv/20260407.txt","label":"openssl-security@openssl.org"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd"],"epss":0.02435,"epssPercentile":0.83574,"ingestedAt":"2026-07-25T23:05:58.156Z","slug":"CVE-2026-28389","body":"## Overview\n\nIssue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.\n\n## Affected\n\n- `openssl >= 1.0.2, < 1.0.2zp`\n- `openssl >= 1.1.1, < 1.1.1zg`\n- `openssl >= 3.0.0, < 3.0.20`\n- `openssl >= 3.3.0, < 3.3.7`\n- `openssl >= 3.4.0, < 3.4.5`\n- `openssl >= 3.5.0, < 3.5.6`\n- `openssl >= 3.6.0, < 3.6.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openssl 3.6.2`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}