CVE-2026-31789
Heap Buffer Overflow in Hexadecimal Conversion
Description
Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow. Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
In plain language
AI Worth attentionCVE-2026-31789 is a bug in OpenSSL where a specially crafted certificate can crash the service or (rarely) allow code execution on 32-bit systems; if you use untrusted X.509 certificates over the network, you should update to the fixed OpenSSL version.
CVE-2026-31789 is a heap buffer overflow in OpenSSL’s hexadecimal conversion of overly large X.509 OCTET STRING extension data (for example SKID/AKID), where attacker-controlled length handling on 32-bit platforms can lead to memory corruption without authentication and without user interaction during certificate processing.
What to do now
- Check whether your system uses OpenSSL and what version is installed (including any 32-bit builds).
- Verify whether your services parse or process X.509 certificates received over the network (for example TLS termination, certificate validation, or any service that prints/logs client certificates).
- Upgrade OpenSSL to a fixed version: 3.0.20, 3.3.7, 3.4.5, 3.5.6, or 3.6.2.
- After upgrading, confirm the running service is using the updated OpenSSL version and re-test certificate handling paths (especially certificate logging/printing).
Empty stringCVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-31789 and every CVE in our database. Create a free account — no credit card required.
Create Free Account