NULL Pointer Dereference Affecting openssl package, versions [3.0.5,3.4.8)[3.5.0,3.5.9)[3.6.0,3.6.5)[4.0.1,4.0.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about NULL Pointer Dereference vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-CONAN-OPENSSL-20537004
  • published6 Oct 2026
  • disclosed29 Sept 2026
  • creditBhabani Sankar Das

Introduced: 29 Sep 2026

NewCVE-2026-75805  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade openssl to version 3.4.8, 3.5.9, 3.6.5, 4.0.3 or higher.

Overview

Affected versions of this package are vulnerable to NULL Pointer Dereference in the CMP client's handling of a revocation response, which compares the certificate named in the response against an issuer name and serial number that are unset when the revocation was requested by PKCS#10 CSR. An attacker can crash the client process by returning a revocation response that names a certificate. This requires the attacker to operate or have compromised the CMP server, or to hold the message protection secret and sit in a MitM position, and clients that identify the certificate by issuer and serial rather than by CSR are unaffected.

CVSS Base Scores

version 4.0
version 3.1