oM noM Security Feeds cve
vulnerability context

CVE-2026-34180

CVSS 7.5 HIGHEPSS 40%CWE-125

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer. More typically such ASN.1 elements would instead be truncated. An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigaby...

Published 2026-06-09 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
7.5 / HIGH
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
40% percentile (score 0.0051)
CWE
CWE-125

source mentions 3

source consensus

  • Bluesky
  • Ubuntu Security Notices
Want the 3-bullet summary of CVE-2026-34180, plus webhook alerts when KEV is updated? Pro is $10/mo.