{"id":"JLSEC-2026-270","summary":"Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7...","details":"Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an `ASN1_TYPE` union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the `PKCS7_digest_from_attributes()` function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function `PKCS7_digest_from_attributes()` accesses the message digest attribute\nvalue without validating its type. When the type is not `V_ASN1_OCTET_STRING`,\nthis results in accessing invalid memory through the `ASN1_TYPE` union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.","modified":"2026-07-25T18:24:50.782224477Z","published":"2026-04-27T18:33:55.942Z","upstream":["CVE-2026-22796","GHSA-r9hf-rxjm-gv2f","EUVD-2026-4813"],"database_specific":{"license":"CC-BY-4.0","sources":[{"url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-22796","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22796","database_specific":{"status":"Modified"},"id":"CVE-2026-22796","imported":"2026-07-17T21:32:17.229Z","modified":"2026-06-17T10:20:26.697Z","published":"2026-01-27T16:16:35.543Z"},{"id":"GHSA-r9hf-rxjm-gv2f","imported":"2026-07-17T21:32:17.401Z","modified":"2026-05-12T15:31:14Z","published":"2026-01-27T18:32:16Z","url":"https://api.github.com/advisories/GHSA-r9hf-rxjm-gv2f","html_url":"https://github.com/advisories/GHSA-r9hf-rxjm-gv2f"},{"modified":"2026-05-12T12:08:55Z","published":"2026-01-27T16:01:28Z","url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-4813","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4813","id":"EUVD-2026-4813","imported":"2026-07-17T21:32:21.450Z"}]},"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html"},{"type":"WEB","url":"https://github.com/advisories/GHSA-r9hf-rxjm-gv2f"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e"},{"type":"WEB","url":"https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22796"},{"type":"WEB","url":"https://openssl-library.org/news/secadv/20260127.txt"}],"affected":[{"package":{"name":"OpenSSL_jll","ecosystem":"Julia","purl":"pkg:julia/OpenSSL_jll?uuid=458c3c95-2e84-50aa-8efc-19380b2a3a95"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.20+0"},{"introduced":"3.5.0+0"},{"fixed":"3.5.5+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-270.json"}},{"package":{"name":"Openresty_jll","ecosystem":"Julia","purl":"pkg:julia/Openresty_jll?uuid=87da34d4-7b1b-5a94-8376-8cb65bf3132c"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.29.203+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-270.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}