{
  "id": "CVE-2026-17510",
  "url": "https://spydr.io/cve/CVE-2026-17510",
  "published": "2026-08-09T02:16:34.117Z",
  "modified": "2026-08-26T16:51:19.490Z",
  "score": 7.5,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "score_source": "CISA ADP",
  "epss": 0.00609,
  "epss_percentile": 0.4735,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [
    "JONASBN"
  ],
  "products": [
    "JONASBN Crypt::OpenSSL::PKCS12"
  ],
  "cwes": [
    "CWE-476"
  ],
  "description": "Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte length with `Renew(*attribute, length, char)`. A zero length attribute makes that a zero size reallocation, which Perl implements as a free returning NULL, so the buffer pointer becomes NULL, the following `strncpy` copies nothing, and the caller dereferences NULL in the `strlen()` it passes to `newSVpvn()`. A zero length BMPSTRING is even length, so the ASN.1 decoder accepts it and the value reaches this code. The UTF8STRING, OCTET STRING and BIT STRING arms size on `length + 1` or `length * 4 + 1` and are unaffected. Any caller that passes an untrusted PKCS#12 file to info_as_hash() can crash the process. info() prints attribute values directly without sizing a buffer and is unaffected.",
  "status": "Deferred",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://github.com/dsully/perl-crypt-openssl-pkcs12/commit/6cb282d8d8e8ded4859551cd2d3cfa7c6028ce48.patch",
      "tags": []
    },
    {
      "url": "https://metacpan.org/release/JONASBN/Crypt-OpenSSL-PKCS12-1.98/source/Changes.md",
      "tags": []
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/08/09/1",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17510",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
