CVE-2026-28388Patch(openssl / openssl)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-04-08); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline9 mentions / 5d
01345Mentions · 2026-04-07: 1Mentions · 2026-04-08: 5Mentions · 2026-04-12: 1Mentions · 2026-04-14: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 3Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-12: 104-0704-0804-1204-1404-16
Signal classification3 categories
Patch
555.6%
Disclosure
333.3%
General
111.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-071
Patch1
2026-04-085
Disclosure2Patch3
2026-04-121
General1
2026-04-141
Disclosure1
2026-04-161
Patch1
Full discourse9 posts
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.54 is now available: • ea-openssl11 patched (CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390) • ea-php85 → 8.5.5, ea-php84 → 8.4.20 • ea-nginx → 1.29.8 (related packages built against it) Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache https://t.co/fXdQMK7NCk

    Post summary

    CPanel released EasyApache 4 v25.54, delivering patches for multiple CVEs affecting ea‑openssl11 and related PHP and Nginx packages.

    00020525
    28.8K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl モジュール更新情報 3.5.6-1 https://kusanagi.tokyo/releases/24085/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 openssl 3.5.6-1 この更新には脆弱性(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-317...

    Post summary

    KUSANAGI's OpenSSL module was updated to version 3.5.6‑1, fixing multiple CVEs such as CVE-2026-31790, 2026-2673, and 2026-28387–28390.

    01010104
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28388 Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extensio… https://www.cve.org/CVERecord?id=CVE-2026-28388

    Post summary

    The CVE record notes a NULL pointer dereference vulnerability in delta CRL processing, but offers no PoC, exploit, or patch details.

    00010139
    57.0K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-28388 impacts openssl-fips-provider-latest in 20 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/469 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    An announcement of a new high‑severity CVE (CVE‑2026‑28388) affecting OpenSSL FIPS provider in several AWS Lambda base images; no exploitation status, patches, or PoC details are shared.

    0000025
    34 followersView on X
  • ますだまさる@m_masaru
    General

    SSLの観点で見ていくと https://nvd.nist.gov/vuln/detail/CVE-2026-28386 CVE-2026-31790 RSA KEMはSSLで使用しないので影響なし CVE-2026-28386 CFBモードはSSLで使用しないので影響なし CVE-2026-28387 DONEはDNSSECベースの証明書検証の仕組みだけどSSL実装レイヤで対応はないので影響なし CVE-2026-28388 delta CRLは、ブラウザは独自にCRLをチェックしているしブラウザ以外は基本CRLをチェックしていないのでSSLに影響なし。SSLでのVPNとかに限定するとあるかも CVE-2026-28389 CMSはSSLで使用していないので影響なし CVE-2026-28390 CMSは同上 CVE-2026-31789 32bit環境で1GiBを超えるOCTET STRINGを含んだ証明書をロードすると発生するのだけど、SSL handshakeのserver cerfificatesのlengthが24bitでmax 16MiBなのでSSLには影響なし

    Post summary

    The post lists several CVEs and concludes that they do not impact SSL, providing only minimal technical remarks and no evidence of PoCs, exploits, active use, or patches.

    00000188
    149 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl Module Update 3.5.6-1 https://kusanagi.tokyo/en/releases/24086/ KUSANAGI 9 modules have been updated. The updated modules are as follows: openssl 3.5.6-1 This update includes support for vulnerability(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388,...

    Post summary

    A Kusanagi module update provides patches for several CVEs, notably CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, and CVE-2026-28388.

    0000091
    200 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in OpenSSL 3.6.x (eight CVEs: RSA KEM, AES-CFB-128, DANE, CMS, delta CRL, hex conversion) 📅 **Timeline:** Disclosure: 2026-03-13, Patch: 2026-04-07 🆔 **CVE-2026-31790** 🆔 **CVE-2026-2673** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 13.657% 🆔 **CVE-2026-28386** 🆔 **CVE-2026-28387** 🆔 **CVE-2026-28388** 🆔 **CVE-2026-28389** 🆔 **CVE-2026-28390** 🆔 **CVE-2026-31789** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** OpenSSL 3.6.x, OpenSSL 3.5.x 🔧 **Fixed Versions:** OpenSSL 3.6.2, OpenSSL 3.5.6 🫨 **Attack Vectors:** - Network-facing TLS/KEM operations (RSASVE) - AES-CFB-128 processing on x86-64 with AVX-512 - DANE TLSA-based client processing - Processing of attacker-controlled CRLs (delta CRL) - Processing of attacker-controlled CMS EnvelopedData (KeyAgree and KeyTransport) - Conversion/printing of large X.509 extension OCTET STRINGS (32-bit platforms) 📝 **Summary:** Multiple memory-safety and parsing bugs in OpenSSL 3.6.x (and some 3.5.x) can cause crashes (DoS), memory disclosure (notably RSA KEM and AES-CFB-128 on AVX‑512), and in constrained cases heap overflow leading to potential code execution on 32‑bit. Prioritize patching systems that perform TLS/KEM operations, process CMS/CRLs/TLSA records, or run on x86‑64 with AVX‑512. 📈 **Impact Scope:** Library-level issues in OpenSSL 3.6.x (and some 3.5.x) enabling crashes (DoS), memory disclosure (RSA KEM, AES-CFB read), and potential memory corruption or code execution (heap overflow on 32-bit); affects servers and clients that use the vulnerable APIs or process untrusted CMS/CRL/certificates. Prioritize AES-CFB-128 on x86-64 with AVX-512 due to memory-read exposure. 🛡️ **Recommended Actions:** - Upgrade affected deployments to OpenSSL 3.6.2 (or OpenSSL 3.5.6 for 3.5 users) and redeploy dependent software immediately. - Apply vendor patches and rebuild/redeploy static-linked/OpenSSL-linked binaries. - For RSASVE (CVE-2026-31790), validate RSA public keys before encapsulation (EVP_PKEY_public_check() / EVP_PKEY_public_check_quick()); avoid processing untrusted CMS/CRL/TLSA inputs where possible. 🪢 **Related Resources:** - https://github.com/openssl/openssl/releases/tag/openssl-3.6.2 - https://openssl-library.org/news/secadv/20260407.txt 🏷 **Tags:** #Cybersecurity #OpenSSL #Crypto

    Post summary

    The post details eight OpenSSL CVEs causing memory-safety and parsing issues, provides patch dates and upgrade guidance, and emphasizes immediate remediation to prevent DoS and potential exploitation.

    0000041
    276 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28388 Denial of Service via NULL Pointer Dereference in Delta CRL Processing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28388

    Post summary

    The post announces CVE‑2026‑28388, describing a denial‑of‑service vulnerability caused by a NULL pointer dereference during Delta CRL processing, without any PoC, exploit code, patch, or active exploitation information.

    0000045
    4.0K followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.2 Is Now Available for Download with Important Security Fixes Patches CVE-2026-31790, CVE-2026-2673, CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, and CVE-2026-31789. https://9to5linux.com/openssl-3-6-2-is-now-available-for-download-with-important-security-fixes

    Post summary

    The post announces the release of OpenSSL 3.6.2, highlighting that it incorporates patches for several CVEs, thereby providing the primary security fix information.

    0000064
    139 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more