Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22795

24
FAUCET Score

CVE-2026-22795 is a type confusion vulnerability in OpenSSL versions 3.0, 3.3, 3.4, 3.5, 3.6, and 1.1.1, allowing an invalid or NULL pointer dereference when processing a malformed PKCS#12 file. This vulnerability has a CVSS score of 5.5 (Medium) due to its local attack vector and user interaction requirement, leading to a Denial of Service. While the impact is limited to a crash on most modern systems, it requires a user or application to process a maliciously crafted file. There is no known active exploitation, public exploit code, or KEV entry, though it has received some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.1, < 1.1.1zeCPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.19CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.3.0, < 3.3.6CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.4.0, < 3.4.4CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.5.0, < 3.5.5CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
4.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 5th percentile among its peer group of 5,765 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (29)

github_advisorypatch availablevia nvd_reference
View patch
jitsipatch availablevia llm_extracted
Fixed in: 3.6.1
View patch
redhatpatch availablevia redhat_api
Product: Cost Management 4Fixed in: costmanagement/costmanagement-metrics-rhel9-operator:sha256:210abe5689a75606b17b1cea30eeef8fd7f0ab39a5d2af6af32e314ed80928c7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:519d4fe184cebe5152f840e9f609fa4705590656ac9bcace2e2e17622ab7e6a8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-ui-rhel9:sha256:4ba29e3e7565cfdfdedcc558bc8495398cee07742fda133b0bc04fd657b908cd
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:ab86ba36e62e8aec5ba48e9e0076b1f8086c48157c85990be0e2ce3e03273016
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/installer-rhel9:sha256:48cf7cf48dfadb17f9357bf1894a5d0393551a893faa8b0ea0e11fe1ffed497f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: openssl-1:3.5.1-7.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: openssl-1:3.5.1-7.el9_7
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: shim-unsigned-aarch64
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: shim-unsigned-x64
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ovmf
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: compat-openssl10
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: edk2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mingw-openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: shim
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: shim-unsigned-x64
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: compat-openssl11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: edk2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: shim
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: shim-unsigned-aarch64
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: shim-unsigned-x64
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Core ServicesFixed in: openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: shim
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: edk2

Vendor Advisories (2)

redhatCVE-2026-22795Low

openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing

Jan 27, 2026
jitsillm-jitsi-40bf01585c2a59b4LOW

Missing ASN1_TYPE validation in PKCS#12 parsing

Jan 27, 2026

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
github.com / openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4
Patch
github.com / openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49
Patch
github.com / openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12
Patch
github.com / openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e
Patch
github.com / openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2
Patch
openssl-library.org / news/secadv/20260127.txt
Vendor Advisory