CVE Explorer
CVE-2026-42765
Issue summary: When a partial-chain certificate verification is enabled
together with OCSP response checking for the whole chain, a NULL dereference
will happen if the verified chain does not have a self-signed trusted anchor,
crashing the process.
Impact summary: A NULL pointer dereference can trigger a crash which leads to a
Denial of Service for an application.
When performing OCSP response checking for certificates in the verification
chain, the code always tries to access the next certifi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"OpenSSL","vendor":"OpenSSL","versions":[{"lessThan":"4.0.1","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"3.6.3","status":"affected","version":"3.6.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:79e99a0e919faeeaadfebfe3f5a93e125afa203c6675aac76b02497e6b6e9636 · sha256:1deaa439cc354568… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:79e99a0e919faeeaadfebfe3f5a93e125afa203c6675aac76b02497e6b6e9636 · sha256:1deaa439cc354568… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-476","description":"CWE-476 NULL Pointer Dereference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:79e99a0e919faeeaadfebfe3f5a93e125afa203c6675aac76b02497e6b6e9636 · sha256:1deaa439cc354568… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"4.0.1 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:79e99a0e919faeeaadfebfe3f5a93e125afa203c6675aac76b02497e6b6e9636 · sha256:1deaa439cc354568… · /containers/cna/references/1
{"name":"3.6.3 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:79e99a0e919faeeaadfebfe3f5a93e125afa203c6675aac76b02497e6b6e9636 · sha256:1deaa439cc354568… · /containers/cna/references/2
{"name":"OpenSSL Advisory","tags":["vendor-advisory"],"url":"https://openssl-library.org/news/secadv/20260609.txt"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:79e99a0e919faeeaadfebfe3f5a93e125afa203c6675aac76b02497e6b6e9636 · sha256:1deaa439cc354568… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.