CVE-2026-45447

HIGH CVSS 3.1: 8.8 EPSS 5.24%
Updated Aug 10, 2026
OpenSSL
Parameter Value
CVSS 8.8 (HIGH)
Affected Versions 1.0.2 — 3.6.3
Fixed In 1.0.2zq
Type CWE-416 (Use After Free), CWE-825
Vendor OpenSSL
Public PoC No

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify().

A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption.

In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 7

Configuration From (including) Up to (excluding)
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
1.0.2 1.0.2zq
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
1.1.1 1.1.1zh
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
3.0.0 3.0.21
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
3.4.0 3.4.6
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
3.5.0 3.5.7
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
3.6.0 3.6.3
Openssl Openssl
cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*

References 24

https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde…
openssl-security@openssl.org
https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d7…
openssl-security@openssl.org
https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefe…
openssl-security@openssl.org
https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e4…
openssl-security@openssl.org
https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce72…
openssl-security@openssl.org
https://openssl-library.org/news/secadv/20260609.txt
openssl-security@openssl.org
https://access.redhat.com/errata/RHSA-2026:25237
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:25239
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:26275
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:26319
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:29197
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:34102
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:35869
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:36215
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:36217
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:39009
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:39012
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:39981
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:44438
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/security/cve/CVE-2026-45447
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://bugzilla.redhat.com/show_bug.cgi?id=2481898
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:47735
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:47737
0b0ca135-0b70-47e7-9f44-1890c2a1c46c