Junglewise Threat Intelligence

CVE-2026-35188: OpenSSL double-free in TLS OCSP stapling response handling

CVE-2026-35188 · Severity: info · Published 2026-06-09

Technologies: OpenSSL Foundation OpenSSL.

Executive brief

OpenSSL is a widely used security library that enables encrypted communications for many applications and services. A vulnerability exists where a malicious server can send a specially crafted response to a client that has 'OCSP stapling' enabled. This can cause the client application to crash (Denial of Service) or potentially allow the attacker to execute unauthorized code on the client's system.

Technical details

A double-free vulnerability (CWE-415) exists in OpenSSL's TLS client implementation during the processing of OCSP stapled responses. When a client with OCSP stapling enabled (via the status_request extension) connects to a malicious server, the server can provide a malformed response that triggers a double-free in the certificate verification path. This occurs because the library incorrectly manages memory when validating the stapled response. While remote code execution is theoretically possible through heap corruption, it is highly complex; the primary impact is a Denial of Service (crash). The vulnerability affects OpenSSL versions 4.0 and 3.6.

Affected products

  • OpenSSL Foundation OpenSSL 4.0, 3.6

Timeline

  • 2026-03-17: disclosed: Reported by Wang Kenaz
  • 2026-03-26: disclosed: Independently reported by Guido Vranken
  • 2026-03-30: disclosed: Independently reported by Aaron Grattafiori
  • 2026-06-09: advisory: OpenSSL Security Advisory published

References