---
cve: "CVE-2026-35189"
severity: "MEDIUM"
cvss: 5.3
epss: "0.1%"
vendor: "OpenSSL"
kev: false
exploited: false
published: "2026-09-29 16:17:07"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-02T17:28:00+02:00"
---

# CVE-2026-35189

> 5.3 MEDIUM · 🧪 PoC

## Beschreibung

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL
distribution points causes disproportionate heap growth when OpenSSL caches
X.509 extensions.

Impact summary: Receiving a crafted certificate from a malicious peer can lead
to significant memory pressure and possible Denial of Service in clients or
in servers that solicit client certificates.

CWE: CWE-770: Allocation of Resources Without Limits or Throttling

Description: A certificate or a set of certificates that fits under the limit for
size of certificates accepted from the peer (~100 KiB) can result in allocation
of several hundred MiB of resident memory on the receiving side
during a normal TLS handshake.  This may be enough to crash the client or
server, if multiple concurrent connections lead to similarly large memory
allocations.

The fix postpones processing of the CRL distribution points extensions in
certificates to the time when the processed value is required for CRL processing.
This avoids keeping large memory allocations for a long time when such
certificates are received.

FIPS impact: no
The affected code is outside the FIPS module boundary.

## CNA-Record (Kanon, cvelistV5)

- CNA: **openssl**
- State: PUBLISHED
- Stand: 2026-09-30 20:11:09

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **yes**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Gering | warn |

## Schwachstellen-Klasse

- **CWE-770** — Allocation of Resources Without Limits or Throttling
  The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

## Angriffsmuster (CAPEC)

- [CAPEC-125 — Flooding](https://capec.mitre.org/data/definitions/125.html) _(Severity: Medium)_
- [CAPEC-130 — Excessive Allocation](https://capec.mitre.org/data/definitions/130.html) _(Severity: Medium)_
- [CAPEC-147 — XML Ping of the Death](https://capec.mitre.org/data/definitions/147.html) _(Severity: Medium)_
- [CAPEC-197 — Exponential Data Expansion](https://capec.mitre.org/data/definitions/197.html) _(Severity: Medium)_
- [CAPEC-229 — Serialized Data Parameter Blowup](https://capec.mitre.org/data/definitions/229.html) _(Severity: High)_
- [CAPEC-230 — Serialized Data with Nested Payloads](https://capec.mitre.org/data/definitions/230.html) _(Severity: High)_
- [CAPEC-231 — Oversized Serialized Data Payloads](https://capec.mitre.org/data/definitions/231.html) _(Severity: High)_
- [CAPEC-469 — HTTP DoS](https://capec.mitre.org/data/definitions/469.html) _(Severity: Low)_

## ATT&CK-Techniken

- [T1498.001 — Network Denial of Service: Direct Network Flood](https://attack.mitre.org/techniques/T1498/001/)
- [T1499 — Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499/)
- [T1499.003 — Endpoint Denial of Service:Application Exhaustion Flood](https://attack.mitre.org/techniques/T1499/003/)
- [T1499.002 — Endpoint Denial of Service: Service Exhaustion Flood](https://attack.mitre.org/techniques/T1499/002/)

## Patch verfügbar (OSV)

- af1775b60dfa141a4ad762585052cabeb9f37e9e (Commit)
- c8bd5a57108599ac650bbae77fcabe3109dab2e8 (Commit)

## BSI-Hinweise (deutsch)

- [OpenSSL: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3638) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren und einen Denial-of-Service-Zustand zu verursachen.

## Referenzen

- <https://openssl-library.org/news/secadv/20260929.txt>
- <https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84>
- <https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f>
- <https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89>
- <https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-35189) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
