#VU125564 Use-after-free in OpenSSL - CVE-2026-28387
Published: April 9, 2026
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in DANE client code when processing server DANE TLSA records during TLSA-based server authentication. A remote attacker can provide crafted TLSA records to execute arbitrary code.
The issue only affects clients that use both PKIX-TA(0) or PKIX-EE(1) certificate usages together with the DANE-TA(2) certificate usage, and the server must publish a TLSA RRset containing both record types.