A vulnerability in OpenSSL CMS AuthEnvelopedData processing allows insufficient validation of attacker-controlled cipher selection and authentication tag length fields within AuthEnvelopedData containers. OpenSSL may incorrectly accept a non-AEAD cipher where authenticated encryption is required, and may also accept excessively short AEAD tag lengths instead of enforcing safe bounds. In one attack path, a legitimate recipientInfo can be reused while the inner algorithm identifier is rewritten to an unauthenticated mode, causing decryption to proceed under the genuine content-encryption key without meaningful integrity verification. In another path, the authentication tag length can be reduced to a single byte, allowing brute-force forgery of modified messages. The flaw affects CMS processing paths such as CMS_decrypt() in affected non-FIPS OpenSSL versions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A flaw in OpenSSL CMS AuthEnvelopedData that allows forgery of encrypted messages, representing a protocol/implementation failure rather than a weakness in the underlying cipher.
An OpenSSL vulnerability addressed in Alpine Linux 3.22.5 and 3.23.5 as part of the June 9, 2026 OpenSSL advisory.
A CMS/PKCS#7 parsing flaw in OpenSSL that allows attacker-controlled AES-GCM authentication tag length reduction, potentially down to one byte, enabling message forgery by brute force.
A CMS/PKCS#7 AuthEnvelopedData parsing flaw in OpenSSL that allows attacker-controlled reduction of the AES-GCM authentication tag length, potentially down to one byte, enabling practical message forgery.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.