Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.
Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).
In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.
This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.
Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.
The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.
OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-libsUpgrade openssl-develUpgrade opensslUpgrade openssl-perl | Feb 3, 2026 | Jan 28, 2026 |
| Alpine Linux | — | Upgrade openssl | Jan 28, 2026 | Jan 27, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-fips-provider-latest-debuginfoUpgrade opensslUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-perlUpgrade openssl-snapsafe-libsUpgrade openssl-fips-provider-latestUpgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade openssl-debuginfoUpgrade openssl-develUpgrade openssl-libs | Feb 20, 2026 | Jan 27, 2026 |
| Debian | — | Upgrade openssl | Jul 23, 2026 | Jul 23, 2026 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Apr 29, 2026 | Apr 28, 2026 |
| Freebsd | — | Upgrade FreeBSDUpgrade openssl35Upgrade openssl34Upgrade openssl36Upgrade opensslUpgrade openssl33 | Jan 28, 2026 | Jan 27, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jan 27, 2026 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libsUpgrade openssl-devel | Jan 30, 2026 | Jan 27, 2026 |
| Redhat_linux | — | Upgrade openssl-perlUpgrade openssl-libsUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-develUpgrade openssl-debugsource | Jan 29, 2026 | Jan 27, 2026 |
| Rocky_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libsUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade openssl-develUpgrade openssl-debugsource | Feb 2, 2026 | Jan 30, 2026 |
| Ubuntu | — | Upgrade libssl3Upgrade libssl3t64Upgrade openssl | Jan 28, 2026 | Jan 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub