CVE-2026-42765
OpenSSL OpenSSL, openssl
Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain...
- CVSS
- 7.5
- EPSS
- 0.51% 40.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.10