{"id":"JLSEC-2026-264","summary":"Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code...","details":"Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an `ASN1_TYPE` union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling `TS_RESP_verify_response()` with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions `ossl_ess_get_signing_cert()` and `ossl_ess_get_signing_cert_v2()`\naccess the signing cert attribute value without validating its type.\nWhen the type is not `V_ASN1_SEQUENCE`, this results in accessing invalid memory\nthrough the `ASN1_TYPE` union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.","modified":"2026-07-25T18:24:50.125708748Z","published":"2026-04-27T18:33:55.942Z","upstream":["CVE-2025-69420","GHSA-w42r-ph9f-9x66","EUVD-2025-206394"],"database_specific":{"sources":[{"html_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69420","database_specific":{"status":"Modified"},"id":"CVE-2025-69420","imported":"2026-07-17T21:31:07.795Z","modified":"2026-06-17T10:00:40.067Z","published":"2026-01-27T16:16:34.317Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-69420"},{"url":"https://api.github.com/advisories/GHSA-w42r-ph9f-9x66","html_url":"https://github.com/advisories/GHSA-w42r-ph9f-9x66","id":"GHSA-w42r-ph9f-9x66","imported":"2026-07-17T21:31:07.942Z","modified":"2026-05-12T15:31:14Z","published":"2026-01-27T18:32:16Z"},{"url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-206394","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206394","id":"EUVD-2025-206394","imported":"2026-07-17T21:31:18.015Z","modified":"2026-05-12T12:08:43Z","published":"2026-01-27T16:01:25Z"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html"},{"type":"WEB","url":"https://github.com/advisories/GHSA-w42r-ph9f-9x66"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69420"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20260127.txt"}],"affected":[{"package":{"name":"OpenSSL_jll","ecosystem":"Julia","purl":"pkg:julia/OpenSSL_jll?uuid=458c3c95-2e84-50aa-8efc-19380b2a3a95"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.20+0"},{"introduced":"3.5.0+0"},{"fixed":"3.5.5+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-264.json"}},{"package":{"name":"Openresty_jll","ecosystem":"Julia","purl":"pkg:julia/Openresty_jll?uuid=87da34d4-7b1b-5a94-8376-8cb65bf3132c"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.19.9+0"},{"fixed":"1.29.203+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-264.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}