CVE Tools

CVE-2026-31789

Heap Buffer Overflow in Hexadecimal Conversion

Published: Apr 7, 2026Updated: Jul 24, 2026 Sources: CVE List NVD csafCWE-787

Description

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow. Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

In plain language

AI Worth attention

CVE-2026-31789 is a bug in OpenSSL where a specially crafted certificate can crash the service or (rarely) allow code execution on 32-bit systems; if you use untrusted X.509 certificates over the network, you should update to the fixed OpenSSL version.

Executive summary

CVE-2026-31789 is a heap buffer overflow in OpenSSL’s hexadecimal conversion of overly large X.509 OCTET STRING extension data (for example SKID/AKID), where attacker-controlled length handling on 32-bit platforms can lead to memory corruption without authentication and without user interaction during certificate processing.

If affected, business impact
Service crashes (denial of service)Possible full process compromiseBusiness disruption from outagesRisk increases for untrusted cert handling

What to do now

  1. Check whether your system uses OpenSSL and what version is installed (including any 32-bit builds).
  2. Verify whether your services parse or process X.509 certificates received over the network (for example TLS termination, certificate validation, or any service that prints/logs client certificates).
  3. Upgrade OpenSSL to a fixed version: 3.0.20, 3.3.7, 3.4.5, 3.5.6, or 3.6.2.
  4. After upgrading, confirm the running service is using the updated OpenSSL version and re-test certificate handling paths (especially certificate logging/printing).
Empty string
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

OpenSSL
oss-project·USaka open ssl
and 1 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 271 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-31789 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store