CVE-2026-28389

Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.


We have discovered 87,429 live websites that are affected by CVE-2026-28389.

Run a Free Instant Scan




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains87,429 live websites (18% of OpenSSL install base)
Vulnerable Versions
  • from 3 through 3.0.20
  • from 3.3 through 3.3.7
  • from 3.4 through 3.4.5
  • from 3.5 through 3.5.6
  • from 3.6 through 3.6.2
Vulnerable Versions Count35 versions ( 48% of all versions)


Common Weakness Enumeration

CWE-476 NULL Pointer Dereference



Details

  • Published - Apr 7, 2026
  • Updated - May 12, 2026

Credits

  • Nathan Sportsman (Praetorian) (reporter)
  • Daniel Rhea (reporter)
  • Jaeho Nam (Seoul National University) (reporter)
  • Muhammad Daffa (reporter)
  • Zhanpeng Liu (Tencent Xuanwu Lab) (reporter)
  • Guannan Wang (Tencent Xuanwu Lab) (reporter)
  • Guancheng Li (Tencent Xuanwu Lab) (reporter)
  • Joshua Rogers (Aisle Research) (reporter)
  • Neil Horman (remediation developer)

Website Distribution by Country

Number of websites using CVE-2026-28389
United States26,799 websites



Netherlands12,335 websites
Germany9,028 websites
Japan3,835 websites
Denmark3,450 websites
France3,085 websites
GB2,943 websites
Canada2,722 websites
Switzerland2,558 websites
Italy1,772 websites

Website Distribution by TLD

Number of websites using CVE-2026-28389
.com28,119 websites
.nl9,488 websites
.org4,777 websites
.de4,256 websites
.net3,831 websites
.edu3,388 websites
.dk3,113 websites
.ch2,483 websites
.ca2,224 websites
.jp1,844 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-28389

Top websites that are affected by CVE-2026-28389. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
****.*****.net Japan*,***
****.org United States*,***
*******.com United States*,***
***********.com Italy*,***
***.***********.com United States*,***
*******.org France*,***
***.***********.com United States*,***
*****************.org United States*,***
****************.ch Switzerland*,***
See full domain list

FAQ

CVE-2026-28389 is NULL Pointer Dereference in OpenSSL
A total of 87,429 websites have been identified as vulnerable to CVE-2026-28389, based on global website indexing conducted by WebTechSurvey.
The OpenSSL is affected by the CVE-2026-28389 vulnerability.
OpenSSL versions up to 3.6.2 are vulnerable to CVE-2026-28389.
CVE-2026-28389 is resolved in version 3.6.2 of OpenSSL.