CVE-2026-63076 | OpenSSL up to 4.0.1 CMP OSSL_CMP_SRV_process_request protectionAlg null pointer dereference
A vulnerability, which was classified as problematic, was found in OpenSSL up to 3.0.21/3.4.6/3.5.7/3.6.3/4.0.1. This affects the function OSSL_CMP_SRV_process_request of the component CMP. The manipulation of the argument protectionAlg results in null pointer dereference.
This vulnerability is known as CVE-2026-63076. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More