Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.
Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.
An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.
Applications that process untrusted CMP/CRMF messages may be affected.
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
{
"cwe_ids": [
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42767.json",
"cna_assigner": "openssl"
}{
"extracted_events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.0.21"
},
{
"introduced": "3.4.0"
},
{
"fixed": "3.4.6"
},
{
"introduced": "3.5.0"
},
{
"fixed": "3.5.7"
},
{
"introduced": "3.6.0"
},
{
"fixed": "3.6.3"
},
{
"introduced": "4.0.0-NA"
},
{
"last_affected": "4.0.0-NA"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
],
"cpe": [
"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*"
]
}[
{
"signature_type": "Function",
"target": {
"file": "crypto/crmf/crmf_lib.c",
"function": "OSSL_CRMF_ENCRYPTEDVALUE_decrypt"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d",
"signature_version": "v1",
"digest": {
"function_hash": "91217218025620681749438914001896975009",
"length": 2457.0
},
"id": "CVE-2026-42767-106bce18"
},
{
"signature_type": "Function",
"target": {
"file": "crypto/crmf/crmf_lib.c",
"function": "OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046",
"signature_version": "v1",
"digest": {
"function_hash": "325408460393520916772416597402285172584",
"length": 2492.0
},
"id": "CVE-2026-42767-2e365102"
},
{
"digest": {
"line_hashes": [
"158143592860499033873604399931203102660",
"2310307610686490434900170873732564816",
"166946920779036293788103000554885336837",
"160560530336034347711027100914902923557",
"307617896841777165862456063373442756103",
"150099295707028111203602953360634233926",
"225656028714529592189036479462720338304",
"84952586632365817100217631231349827711",
"139151340687842933703999904366776901818",
"206543994600228090187663760716588651494",
"114949461791416633062388642277476779956",
"50177780468873553555030560247521475161"
],
"threshold": 0.9
},
"target": {
"file": "crypto/crmf/crmf_lib.c"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873",
"id": "CVE-2026-42767-67f1e926",
"signature_type": "Line",
"signature_version": "v1"
},
{
"signature_type": "Function",
"target": {
"file": "crypto/crmf/crmf_lib.c",
"function": "OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774",
"signature_version": "v1",
"digest": {
"function_hash": "233325686147742210662481575423982742364",
"length": 2139.0
},
"id": "CVE-2026-42767-6a92a7c7"
},
{
"digest": {
"line_hashes": [
"158143592860499033873604399931203102660",
"60688306397627978211701846104401847170",
"77688536731994844037099143947334460932",
"160001391318980809684469413508905282423",
"62352660086429031702055047130064202397",
"338937022658953388516261522269428062787",
"313096676879358747269849563288427874290",
"261523757798894084583931286852707949089",
"175766670349288168436146356470242879454",
"164276849464106337402847898219872288169",
"114949461791416633062388642277476779956",
"50177780468873553555030560247521475161"
],
"threshold": 0.9
},
"target": {
"file": "crypto/crmf/crmf_lib.c"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774",
"id": "CVE-2026-42767-6d7f3b94",
"signature_type": "Line",
"signature_version": "v1"
},
{
"signature_type": "Line",
"target": {
"file": "crypto/crmf/crmf_lib.c"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d",
"signature_version": "v1",
"digest": {
"line_hashes": [
"158143592860499033873604399931203102660",
"2310307610686490434900170873732564816",
"166946920779036293788103000554885336837",
"160560530336034347711027100914902923557",
"307617896841777165862456063373442756103",
"150099295707028111203602953360634233926",
"225656028714529592189036479462720338304",
"84952586632365817100217631231349827711",
"139151340687842933703999904366776901818",
"206543994600228090187663760716588651494",
"114949461791416633062388642277476779956",
"50177780468873553555030560247521475161"
],
"threshold": 0.9
},
"id": "CVE-2026-42767-6f387f04"
},
{
"signature_version": "v1",
"target": {
"file": "crypto/crmf/crmf_lib.c",
"function": "OSSL_CRMF_ENCRYPTEDVALUE_decrypt"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873",
"digest": {
"function_hash": "177468829496979591909634834209401852632",
"length": 2300.0
},
"id": "CVE-2026-42767-d047643f",
"signature_type": "Function"
},
{
"signature_version": "v1",
"target": {
"file": "crypto/crmf/crmf_lib.c",
"function": "OSSL_CRMF_ENCRYPTEDVALUE_decrypt"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f",
"digest": {
"function_hash": "91217218025620681749438914001896975009",
"length": 2457.0
},
"id": "CVE-2026-42767-d61d12de",
"signature_type": "Function"
},
{
"signature_type": "Line",
"target": {
"file": "crypto/crmf/crmf_lib.c"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046",
"signature_version": "v1",
"digest": {
"line_hashes": [
"158143592860499033873604399931203102660",
"60688306397627978211701846104401847170",
"77688536731994844037099143947334460932",
"160001391318980809684469413508905282423",
"307617896841777165862456063373442756103",
"150099295707028111203602953360634233926",
"262624842520804075076259156904012189589",
"261523757798894084583931286852707949089",
"175766670349288168436146356470242879454",
"164276849464106337402847898219872288169",
"114949461791416633062388642277476779956",
"50177780468873553555030560247521475161"
],
"threshold": 0.9
},
"id": "CVE-2026-42767-e4725b98"
},
{
"signature_type": "Line",
"target": {
"file": "crypto/crmf/crmf_lib.c"
},
"deprecated": false,
"source": "https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f",
"signature_version": "v1",
"digest": {
"line_hashes": [
"158143592860499033873604399931203102660",
"2310307610686490434900170873732564816",
"166946920779036293788103000554885336837",
"160560530336034347711027100914902923557",
"307617896841777165862456063373442756103",
"150099295707028111203602953360634233926",
"225656028714529592189036479462720338304",
"84952586632365817100217631231349827711",
"139151340687842933703999904366776901818",
"206543994600228090187663760716588651494",
"114949461791416633062388642277476779956",
"50177780468873553555030560247521475161"
],
"threshold": 0.9
},
"id": "CVE-2026-42767-fadb862b"
}
]
"2026-07-14T16:46:15Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42767.json"