REDHAT-BUG-2502751: Medium severity OpenSSL OpenSSL vulnerability
Published Jul 20, 2026
·Updated
When a server has wantClientAuth and the client sends a nocertificate alert, any client certificates are not verified.
Affected Software
1 affected component
OpenSSL OpenSSL
Event History
Jul 20, 2026
Data Sourced
via Red Hat·12:50 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2502751?
The severity of REDHAT-BUG-2502751 is classified as medium with a risk level of 4.
2
What is the impact of the vulnerability REDHAT-BUG-2502751?
REDHAT-BUG-2502751 allows client certificates to be unverified when a no_certificate alert is sent, posing a risk to server authentication.
3
How do I fix REDHAT-BUG-2502751?
To mitigate REDHAT-BUG-2502751, ensure proper client certificate verification settings in your OpenSSL configuration.
4
Which software is affected by REDHAT-BUG-2502751?
The vulnerability REDHAT-BUG-2502751 affects OpenSSL versions that have the wantClientAuth option enabled.
5
When was REDHAT-BUG-2502751 published?
REDHAT-BUG-2502751 was published on July 20, 2026.