https://seclists.org/oss-sec/2026/q3/443: CVE-2026-54876: OpenSSL: Client-Side Memory Leak in OCSP sponse Checking
Published Aug 5, 2026
·Updated
Affected Software
2 affected components
OpenSSL OpenSSL 4.0=4.0
OpenSSL OpenSSL 3.6=3.6
Frequently Asked Questions
1
What is the severity of CVE-2026-54876?
The severity of CVE-2026-54876 is classified as low.
2
What type of vulnerability is CVE-2026-54876?
CVE-2026-54876 is a client-side memory leak vulnerability in OCSP response checking.
3
How does CVE-2026-54876 impact OpenSSL users?
CVE-2026-54876 can lead to a memory leak when connecting to a malicious TLS server.
4
Which versions of OpenSSL are affected by CVE-2026-54876?
CVE-2026-54876 affects OpenSSL version 4.0 and OpenSSL version 3.6.
5
How can I mitigate CVE-2026-54876?
To mitigate CVE-2026-54876, users should update to a patched version of OpenSSL provided after August 5, 2026.