---
cve: "CVE-2026-63073"
severity: "CRITICAL"
cvss: 9.8
epss: "93%"
vendor: "OpenSSL"
kev: false
exploited: false
published: "2026-08-25 13:19:26"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-19T06:21:44+02:00"
---

# CVE-2026-63073

> 9.8 CRITICAL · 🧪 PoC

## Beschreibung

Issue summary: OpenSSL CMP response validation passed an unexpected response
sender distinguished name directly as the format string to `ERR_raise_data()`.

Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client
that enforces an expected sender or uses a pinned server certificate whose
subject becomes the default expected sender.

CWE: CWE-134 (Use of Externally-Controlled Format String)

Description: When validating a received CMP message, ossl_cmp_msg_check_update()
converts the peer-supplied sender distinguished name with X509_NAME_oneline()
and passes it directly as the format argument to ERR_raise_data(). Percent
characters survive the conversion, so a sender DN such as "CN=%s%n" reaches
BIO_vsnprintf() as an attacker-controlled format string with no matching variadic
arguments. This path is only reached when the caller configures an expected
sender or pins a server certificate, which is the normal configuration for a
CMP client validating server responses.

Since the attacker controls the format string but none of the variadic
arguments, such specifiers as %s and %n dereference or write through unrelated
stack contents and crash the client. The reliable consequence is a denial of
service, when the response comes from a malicious or intercepted CMP endpoint.
There is no controlled memory write, arbitrary-address read, or reliable path
to remote code execution.

FIPS impact: no

No FIPS modules are affected by this issue, as the CMP protocol
implementation is outside the OpenSSL FIPS module boundary.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-134** — Use of Externally-Controlled Format String
  The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

## Angriffsmuster (CAPEC)

- [CAPEC-67 — String Format Overflow in syslog()](https://capec.mitre.org/data/definitions/67.html) _(Severity: Very High)_
- [CAPEC-135 — Format String Injection](https://capec.mitre.org/data/definitions/135.html) _(Severity: High)_

## Patch verfügbar (OSV)

- 0c5d912057abf47505b4ad455da49fbab99b76f1 (Commit)
- f4dc4d58b48d346a8270183f89acf826d459b0ca (Commit)

## Referenzen

- <https://openssl-library.org/news/secadv/20260825.txt>
- <https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21>
- <https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29>
- <https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca>
- <https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-63073) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
