CVE-2026-28390Patch(openssl / openssl)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openssl openssl systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 4 mentions (2026-04-08); latest day: 1
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline11 mentions / 7d
01234Mentions · 2026-04-07: 2Mentions · 2026-04-08: 4Mentions · 2026-04-12: 1Mentions · 2026-04-14: 1Mentions · 2026-04-16: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-22: 1Patch / Workaround · 2026-04-07: 2Patch / Workaround · 2026-04-08: 2Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-14: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-0704-0804-1204-1404-1604-2204-23
Signal classification4 categories
Patch
545.5%
Disclosure
436.4%
General
19.1%
PoC
19.1%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-04-072
Patch2
2026-04-084
Disclosure3Patch1
2026-04-121
General1
2026-04-141
Disclosure1
2026-04-161
Patch1
2026-04-221
PoC1
2026-04-231
Patch1
Full discourse11 posts
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.54 is now available: • ea-openssl11 patched (CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390) • ea-php85 → 8.5.5, ea-php84 → 8.4.20 • ea-nginx → 1.29.8 (related packages built against it) Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache https://t.co/fXdQMK7NCk

    Post summary

    This post announces that EasyApache 4 version 25.54 includes patches for several CVEs, primarily updating packages and fixing the vulnerabilities.

    00020525
    28.8K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl モジュール更新情報 3.5.6-1 https://kusanagi.tokyo/releases/24085/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 openssl 3.5.6-1 この更新には脆弱性(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-317...

    Post summary

    This release update for the OpenSSL module includes a new version (3.5.6-1) that patches several CVEs, providing a vendor-imposed fix.

    01010104
    200 followersView on X
  • Kazuki Omo@omokazuki
    Patch

    OpenSSLの脆弱性(Moderate: CVE-2026-31790, Low: CVE-2026-28386〜CVE-2026-28390, CVE-2026-31789)と3.6.2, 3.5.6, 3.4.5, 3.3.7, 3.0.20, 1.1.1zg, 1.0.2zpリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssl #openssl https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260408/

    Post summary

    The post announces new OpenSSL releases that address CVE-2026-31790 and related low‑severity CVEs, thereby providing a patch update for affected versions.

    00020185
    370 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Patched CVE-2026-28390 (OpenSSL NULL crash)? Good. Now learn why the next CMS vulnerability will hit you too. Read more -> https://tinyurl.com/4n6bb6p9 #openSUSE https://t.co/YpULqkOTIv

    Post summary

    The tweet announces that CVE-2026-28390 (an OpenSSL NULL crash) has been patched, offers no PoC or exploit details, and hints at upcoming CMS vulnerabilities.

    1000072
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    PoC

    One crafted TLS packet = your web server dead. CVE-2026-28390 is the latest OpenSSL NULL pointer. We built a distro-agnostic fix script + iptables workaround. Plus: the one book that teaches you to spot these bugs in C code. Read more: 👉 https://tinyurl.com/28m6hdkc #SUSE https://t.co/9gN77qOZdL

    Post summary

    The tweet presents a proof‑of‑concept attack using a crafted TLS packet to trigger a NULL pointer in OpenSSL (CVE‑2026‑28390) and provides a distro‑agnostic fix script and iptables workaround.

    1000092
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-28390 impacts openssl-fips-provider-latest in 20 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/471 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    AWS has reported a new HIGH severity CVE-2026-28390 affecting the openssl-fips-provider in Lambda base images, with details provided via GitHub and Lambdawatchdog.

    0000030
    34 followersView on X
  • ますだまさる@m_masaru
    General

    SSLの観点で見ていくと https://nvd.nist.gov/vuln/detail/CVE-2026-28386 CVE-2026-31790 RSA KEMはSSLで使用しないので影響なし CVE-2026-28386 CFBモードはSSLで使用しないので影響なし CVE-2026-28387 DONEはDNSSECベースの証明書検証の仕組みだけどSSL実装レイヤで対応はないので影響なし CVE-2026-28388 delta CRLは、ブラウザは独自にCRLをチェックしているしブラウザ以外は基本CRLをチェックしていないのでSSLに影響なし。SSLでのVPNとかに限定するとあるかも CVE-2026-28389 CMSはSSLで使用していないので影響なし CVE-2026-28390 CMSは同上 CVE-2026-31789 32bit環境で1GiBを超えるOCTET STRINGを含んだ証明書をロードすると発生するのだけど、SSL handshakeのserver cerfificatesのlengthが24bitでmax 16MiBなのでSSLには影響なし

    Post summary

    The post lists multiple CVEs and explains that none of them impact SSL implementations, citing high‑level technical reasons for each.

    00000188
    149 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in OpenSSL 3.6.x (eight CVEs: RSA KEM, AES-CFB-128, DANE, CMS, delta CRL, hex conversion) 📅 **Timeline:** Disclosure: 2026-03-13, Patch: 2026-04-07 🆔 **CVE-2026-31790** 🆔 **CVE-2026-2673** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 13.657% 🆔 **CVE-2026-28386** 🆔 **CVE-2026-28387** 🆔 **CVE-2026-28388** 🆔 **CVE-2026-28389** 🆔 **CVE-2026-28390** 🆔 **CVE-2026-31789** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** OpenSSL 3.6.x, OpenSSL 3.5.x 🔧 **Fixed Versions:** OpenSSL 3.6.2, OpenSSL 3.5.6 🫨 **Attack Vectors:** - Network-facing TLS/KEM operations (RSASVE) - AES-CFB-128 processing on x86-64 with AVX-512 - DANE TLSA-based client processing - Processing of attacker-controlled CRLs (delta CRL) - Processing of attacker-controlled CMS EnvelopedData (KeyAgree and KeyTransport) - Conversion/printing of large X.509 extension OCTET STRINGS (32-bit platforms) 📝 **Summary:** Multiple memory-safety and parsing bugs in OpenSSL 3.6.x (and some 3.5.x) can cause crashes (DoS), memory disclosure (notably RSA KEM and AES-CFB-128 on AVX‑512), and in constrained cases heap overflow leading to potential code execution on 32‑bit. Prioritize patching systems that perform TLS/KEM operations, process CMS/CRLs/TLSA records, or run on x86‑64 with AVX‑512. 📈 **Impact Scope:** Library-level issues in OpenSSL 3.6.x (and some 3.5.x) enabling crashes (DoS), memory disclosure (RSA KEM, AES-CFB read), and potential memory corruption or code execution (heap overflow on 32-bit); affects servers and clients that use the vulnerable APIs or process untrusted CMS/CRL/certificates. Prioritize AES-CFB-128 on x86-64 with AVX-512 due to memory-read exposure. 🛡️ **Recommended Actions:** - Upgrade affected deployments to OpenSSL 3.6.2 (or OpenSSL 3.5.6 for 3.5 users) and redeploy dependent software immediately. - Apply vendor patches and rebuild/redeploy static-linked/OpenSSL-linked binaries. - For RSASVE (CVE-2026-31790), validate RSA public keys before encapsulation (EVP_PKEY_public_check() / EVP_PKEY_public_check_quick()); avoid processing untrusted CMS/CRL/TLSA inputs where possible. 🪢 **Related Resources:** - https://github.com/openssl/openssl/releases/tag/openssl-3.6.2 - https://openssl-library.org/news/secadv/20260407.txt 🏷 **Tags:** #Cybersecurity #OpenSSL #Crypto

    Post summary

    An alert detailing multiple memory-safety and parsing bugs in OpenSSL 3.6.x, with patch releases, attack vectors, and mitigation guidance, but no active exploitation or PoC evidence.

    0000041
    276 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28390 NULL Pointer Dereference in CMS EnvelopedData KeyTransportRecipientInfo Processing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28390

    Post summary

    A new vulnerability, CVE‑2026‑28390, has been disclosed as a null pointer dereference within CMS EnvelopedData KeyTransportRecipientInfo processing.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28390 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applica… https://www.cve.org/CVERecord?id=CVE-2026-28390

    Post summary

    The post announces CVE‑2026‑28390, describing a NULL pointer dereference that can occur when processing a crafted CMS EnvelopedData message with KeyTransportRecipientInfo.

    00000132
    57.0K followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.2 Is Now Available for Download with Important Security Fixes Patches CVE-2026-31790, CVE-2026-2673, CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, and CVE-2026-31789. https://9to5linux.com/openssl-3-6-2-is-now-available-for-download-with-important-security-fixes

    Post summary

    The article announces the release of OpenSSL 3.6.2 with patches for several CVEs, focusing on the availability of security fixes without providing exploit details.

    0000064
    139 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more