CVE-2026-28390: Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.
Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.
When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.
Applications and services that call CMSdecrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
Other sources
Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28390?
CVE-2026-28390 is considered a critical vulnerability as it can lead to a potential application crash due to a NULL pointer dereference.
How do I fix CVE-2026-28390?
To fix CVE-2026-28390, upgrade your OpenSSL library to the latest version that addresses this vulnerability.
What applications are affected by CVE-2026-28390?
Applications that process attacker-controlled CMS data using vulnerable versions of OpenSSL are affected by CVE-2026-28390.
What happens if I am affected by CVE-2026-28390?
If your application is affected by CVE-2026-28390, it may crash when processing maliciously crafted CMS messages.
Is there a workaround for CVE-2026-28390?
Currently, there are no known workarounds for CVE-2026-28390 aside from upgrading to a patched version of OpenSSL.