---
cve: "CVE-2026-14457"
severity: "HIGH"
cvss: 7.5
epss: "1%"
vendor: "OpenSSL"
kev: false
exploited: false
published: "2026-08-25 13:17:49"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T00:02:33+02:00"
---

# CVE-2026-14457

> 7.5 HIGH · 🧪 PoC

## Beschreibung

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)
enabled, and only the private key (with no associated certificate) configured locally,
a NULL pointer dereference may occur when the remote peer solicits raw public keys and
also sends the typically omitted "signature_algorithms_cert" TLS extension.

Impact summary: The impact is limited to a possible Denial of Service as a result of
an application abort, no data disclosure or remote command execution are possible.

CWE: CWE-476: NULL Pointer Dereference

Description: While a passing comment in sample code in the documentation suggests
that key-only RPK configurations are supported, the best-practice RPK configuration
is to always configure a corresponding certificate (possibly self-signed or
signed by any convenient CA).

When the private key is configured along with a matching certificate, the
"signature_algorithms_cert" extension is handled reliably even without the
fix, and peer clients or servers that don't support raw public keys may be
able to complete a TLS connection by pinning or verifying the corresponding
certificate or its public key.

Deployments that prefer to configure just a private key with no certificate
need to upgrade to an updated release as noted below.

FIPS impact: no

No FIPS modules are affected by this issue, as the SSL protocol implementation
is outside the OpenSSL FIPS module boundary.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-476** — NULL Pointer Dereference
  The product dereferences a pointer that it expects to be valid but is NULL.

## Patch verfügbar (OSV)

- 0c5d912057abf47505b4ad455da49fbab99b76f1 (Commit)
- f4dc4d58b48d346a8270183f89acf826d459b0ca (Commit)

## Referenzen

- <https://openssl-library.org/news/secadv/20260825.txt>
- <https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b>
- <https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1>
- <https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f>
- <https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-14457) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
