---
id: CVE-2018-0732
title: >-
  During key agreement in a TLS handshake using a DH(E) based ciphersuite a
  malicious server can send a very large prime value to the client
summary: >-
  During key agreement in a TLS handshake using a DH(E) based ciphersuite a
  malicious server can send a very large prime value to the client. This will
  cause the client to spend an unreasonably long period of time generating a key
  for this…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-320
vendor: openssl
product: openssl
affected:
  - 'openssl >= 1.0.2, <= 1.0.2o'
  - 'openssl >= 1.1.0, <= 1.1.0h'
  - ubuntu_linux = 12.04
  - ubuntu_linux = 14.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 17.10
  - ubuntu_linux = 18.04
  - debian_linux = 8.0
  - 'node.js >= 6.0.0, < 6.8.1'
  - 'node.js >= 6.9.0, < 6.14.4'
  - 'node.js >= 8.0.0, < 8.8.1'
  - 'node.js >= 8.9.0, < 8.11.4'
  - 'node.js >= 10.0.0, < 10.9.0'
patched:
  - node.js 10.9.0
published: '2018-06-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:42.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-0732'
references:
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
    label: openssl-security@openssl.org
  - url: 'http://www.securityfocus.com/bid/104442'
    label: openssl-security@openssl.org
  - url: 'http://www.securitytracker.com/id/1041090'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:2552'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:2553'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:3221'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:3505'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:1296'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:1297'
    label: openssl-security@openssl.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:1543'
    label: openssl-security@openssl.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-419820.pdf'
    label: openssl-security@openssl.org
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3984ef0b72831da8b3ece4745cac4f8575b19098
    label: openssl-security@openssl.org
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ea7abeeabf92b7aca160bdd0208636d4da69f4f4
    label: openssl-security@openssl.org
  - url: 'https://lists.debian.org/debian-lts-announce/2018/07/msg00043.html'
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
    label: openssl-security@openssl.org
  - url: 'https://nodejs.org/en/blog/vulnerability/august-2018-security-releases/'
    label: openssl-security@openssl.org
  - url: 'https://security.gentoo.org/glsa/201811-03'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20181105-0001/'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20190118-0002/'
    label: openssl-security@openssl.org
  - url: 'https://securityadvisories.paloaltonetworks.com/Home/Detail/133'
    label: openssl-security@openssl.org
  - url: 'https://usn.ubuntu.com/3692-1/'
    label: openssl-security@openssl.org
  - url: 'https://usn.ubuntu.com/3692-2/'
    label: openssl-security@openssl.org
  - url: 'https://www.debian.org/security/2018/dsa-4348'
    label: openssl-security@openssl.org
  - url: 'https://www.debian.org/security/2018/dsa-4355'
    label: openssl-security@openssl.org
  - url: 'https://www.openssl.org/news/secadv/20180612.txt'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: openssl-security@openssl.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: openssl-security@openssl.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
    label: openssl-security@openssl.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: openssl-security@openssl.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2018-12'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2018-13'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2018-14'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2018-17'
    label: openssl-security@openssl.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/104442'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1041090'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:2552'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:2553'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:3221'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:3505'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:1296'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:1297'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:1543'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-419820.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3984ef0b72831da8b3ece4745cac4f8575b19098
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ea7abeeabf92b7aca160bdd0208636d4da69f4f4
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2018/07/msg00043.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://nodejs.org/en/blog/vulnerability/august-2018-security-releases/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/201811-03'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20181105-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20190118-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://securityadvisories.paloaltonetworks.com/Home/Detail/133'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/3692-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/3692-2/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2018/dsa-4348'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2018/dsa-4355'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openssl.org/news/secadv/20180612.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2018-12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2018-13'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2018-14'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2018-17'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.48831
epssPercentile: 0.98849
ingestedAt: '2026-10-08T23:16:47.290Z'
---

## Overview

During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).

## Affected

- `openssl >= 1.0.2, <= 1.0.2o`
- `openssl >= 1.1.0, <= 1.1.0h`
- `ubuntu_linux = 12.04`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 17.10`
- `ubuntu_linux = 18.04`
- `debian_linux = 8.0`
- `node.js >= 6.0.0, < 6.8.1`
- `node.js >= 6.9.0, < 6.14.4`
- `node.js >= 8.0.0, < 8.8.1`
- `node.js >= 8.9.0, < 8.11.4`
- `node.js >= 10.0.0, < 10.9.0`

## Remediation

Upgrade past the affected range:

- `node.js 10.9.0`
