Executive brief
OpenSSL contains a cryptographic vulnerability in how it handles encrypted email and data messages. An attacker who can send specially crafted messages and observe how the system responds may be able to slowly decrypt sensitive information or forge digital signatures. While technically complex to execute, this could lead to the exposure of private communications or the unauthorized signing of documents.
Technical details
The CMS_decrypt and PKCS7_decrypt functions are vulnerable to a Bleichenbacher-style adaptive-chosen-ciphertext attack. The vulnerability exists in two variants: first, when decryption is performed without a recipient certificate, OpenSSL fails to stop at the first successful KeyTransRecipientInfo (KTRI) iteration; second, when a certificate is provided but not found, a random key substitution occurs. If an attacker can observe error codes or decryption output, they can create an oracle to decrypt RSA ciphertexts or forge PKCS#1 v1.5 signatures. The fix implements an 'implicit rejection' mechanism in EVP_PKEY_decrypt() to ensure deterministic output and prevent side-channel leakage.
Affected products
- OpenSSL Foundation OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, 1.0.2
Timeline
- 2026-06-09: advisory: Original advisory published by OpenSSL Foundation
References
- https://github.com/openssl/security/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f
- https://github.com/openssl/security/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d
- https://github.com/openssl/security/commit/dd68364107a58841c0a2546812518b65d3a23abd
- https://github.com/openssl/security/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e
- https://openssl-library.org/news/secadv/20260609.txt