← Back to CVE List
Vulnerability Intelligence Report
Untrusted Sender DN Used as Format String in CMP Response Validation

CVE-2026-63073

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender. CWE: CWE-134 (Use of Externally-Controlled Format String) Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as "CN=%s%n" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses. Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.41%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-134 ↗Use of Externally-Controlled Format String

Affected Products & Versions

Vendor Product Affected Versions
OpenSSL OpenSSL 4.0.0 < 4.0.2 (affected), 3.6.0 < 3.6.4 (affected), 3.5.0 < 3.5.8 (affected), 3.4.0 < 3.4.7 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.409%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityOpenSSL Software Foundation · Vendor · USA
Reserved2026-07-15T13:10:26
Published2026-08-25T12:59:43
Patch Date2026-08-25
Last Updated2026-08-31T19:12:54

LINK COPIED TO CLIPBOARD