OpenSSL disclosed CVE-2026-54876, a low-severity flaw that lets a malicious TLS server trigger a client-side memory leak during OCSP response checking. The bug appears when a TLS client has explicitly enabled OCSP validation and processes a BasicOCSPResponse with an empty SingleResponse sequence, leaving an allocated OCSP_BASICRESP structure unfreed. By repeating handshakes and tuning the leaked memory per connection, an attacker could exhaust memory in long-running client applications and cause a denial of service.
The issue affects OpenSSL 4.0 and 3.6 but not 3.5, 3.4, 3.0, 1.1.1, or 1.0.2, and OpenSSL said its FIPS modules are not impacted because the vulnerable code sits outside the FIPS boundary. The fix changes check_cert_ocsp_resp() in crypto/x509/x509_vfy.c so error handling routes through cleanup and frees the OCSP basic response instead of returning early; patches are already available in commits d8c5104 and 155b5fe and are slated for inclusion in releases 4.0.2 and 3.6.4.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
OpenSSL disclosed CVE-2026-54876 as a low-severity client-side memory leak in OCSP response checking that a malicious TLS server could trigger when clients explicitly enabled OCSP response verification. The advisory said OpenSSL 4.0 and 3.6 were affected, while several earlier branches were not, and recommended upgrading once fixed releases become available.
OpenSSL published code commits 155b5fe and d8c5104 that changed check_cert_ocsp_resp() to route empty OCSP BasicResponse handling through cleanup, preventing the OCSP_BASICRESP object from leaking. These commits made the fixes available in the Git repository ahead of release versions 3.6.4 and 4.0.2.
OpenSSL said Zhenzhe Shao independently reported the same OCSP response checking memory leak later in June. The eventual fix was developed by Mounir Idrassi.
OpenSSL said Bhabani Sankar Das reported the issue that became CVE-2026-54876. The flaw involved a client-side memory leak in OCSP response checking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceopenwall.com
Open sourceopenssl-library.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.