CVE-2026-35189

MEDIUMPre-NVD 5.35.3—
EchelonGraph scoreHIGH confidence

Score 5.3 from GitHub Security Advisory published 2026-09-29. CISA-ADP (Vulnrichment) CVSS v3.1 baseline 5.3; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: cisa-adp, epss, ghsa
Trending — Patch released this week
5.3EG
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: 0.3%CVSS: 5.3Exploit: None knownExposed services: Not assessed

A fix is available — apply it.

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.

Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.

CWE: CWE-770: Allocation of Resources Without Limits or Throttling

Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.

The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.

FIPS impact: no The affected code is outside the FIPS module boundary.

CVSS v3
5.3
EG Score
5.3MEDIUMhigh confidence
EG Risk
39
EG Risk 39/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity53% × 45%
Exploitation0% × 40%
Automatability100% × 15%
CISA SSVC: Track at low or medium mission impact; Attend at high (mission-essential systems).
Action: A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.
EPSS PROB
0.3%
EPSS %ILE
17th
KEV
Not listed

CISA SSVCTrack at low or medium mission impact; Attend at high (mission-essential systems).

A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.

Exploitation none (CISA Vulnrichment) · Automatable yes (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

September 29, 2026

Last Modified

September 30, 2026

Advisory Details (5)

Auto-updated Sep 30, 2026
Patch available. Sources: github_commit.
github_commit

commit c72ae182cac1 (openssl/openssl)

Fix landed in openssl/openssl commit c72ae182cac1 — awaiting tagged release

https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9
github_commit

commit 8e0efc7549b7 (openssl/openssl)

Fix landed in openssl/openssl commit 8e0efc7549b7 — awaiting tagged release

https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f
github_commit

commit 3842516cc15e (openssl/openssl)

Fix landed in openssl/openssl commit 3842516cc15e — awaiting tagged release

https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89
github_commit

commit 2b93c73b2c70 (openssl/openssl)

Fix landed in openssl/openssl commit 2b93c73b2c70 — awaiting tagged release

https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84

Patch Availability(4)

Vendor / EcosystemFixed in / PatchReleasedSource
ubuntuopenssl-provider-legacy (3.5.5-1ubuntu3.6) @ resolute2026-10-03ubuntu
ubuntuopenssl (1.0.1f-1ubuntu2.27+esm17) @ trusty2026-10-03ubuntu
redhatopenssl-main-3.5.9-0.1.hum12026-09-30redhat
redhatopenssl3-main-3.5.9-0.1.hum12026-09-30redhat

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Additional Vendor Advisories

(2)

Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.

Data Freshness Timeline

(refreshed 22× in last 7d / 22× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-10-03 19:41 UTCEG score recompute
  2. 2026-10-03 19:41 UTCVendor advisory
  3. 2026-10-03 19:41 UTCGHSA enrichment
  4. 2026-10-03 14:25 UTCEPSS rescore
  5. 2026-10-02 20:19 UTCEG score recompute
  6. 2026-10-02 20:19 UTCVendor advisory
  7. 2026-10-02 20:19 UTCGHSA enrichment
  8. 2026-10-01 20:55 UTCEG score recompute
  9. 2026-10-01 20:55 UTCVendor advisory
  10. 2026-10-01 20:55 UTCGHSA enrichment
  11. 2026-10-01 19:49 UTCEPSS rescore
  12. 2026-09-30 21:29 UTCVendor advisory
  13. 2026-09-30 21:29 UTCGHSA enrichment
  14. 2026-09-30 20:26 UTCEG score recompute▲ 5.30
  15. 2026-09-30 20:26 UTCVendor advisory
  16. 2026-09-30 20:26 UTCGHSA enrichment
  17. 2026-09-30 20:25 UTCMITRE cvelistV5CVSS v3 → 5.3 · severity → MEDIUM
  18. 2026-09-30 15:03 UTCEPSS rescore
  19. 2026-09-29 22:00 UTCGHSA enrichment
  20. 2026-09-29 16:24 UTCNVD update
  21. 2026-09-29 15:38 UTCEG score recompute
  22. 2026-09-29 15:38 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-35189?
CVE-2026-35189 is a medium vulnerability published on September 29, 2026. Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of…
When was CVE-2026-35189 disclosed?
CVE-2026-35189 was first published on September 29, 2026, with the most recent update on September 30, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-35189 actively exploited?
CVE-2026-35189 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0.3% probability of exploitation in the next 30 days (17th percentile of EPSS-scored CVEs).
What is the CVSS score of CVE-2026-35189?
CVE-2026-35189 has a CVSS v3.1 base score of 5.3 (CISA-ADP / Vulnrichment enrichment; NVD's own analysis pending).
How do I remediate CVE-2026-35189?
A fix for CVE-2026-35189 is available: update to the fixed version the vendor names in its advisory. The vendor advisories EchelonGraph has for CVE-2026-35189 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-35189

Explore →

Is Your Infrastructure Affected by CVE-2026-35189?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.