CVE-2026-34182
OpenSSL OpenSSL, openssl
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message. In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher. OpenSSL erroneously allows this selection, and attempts to decry...
- CVSS
- 9.1
- EPSS
- 0.35% 27.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.10