MEDIUM

CVE-2026-22795

CVSS v3

5.5

MEDIUM

EPSS Score

0.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to

Technical details

CVSS v3 Vector
3.1
Published
1/27/2026
Last Modified
2/2/2026

Frequently asked questions

What is CVE-2026-22795?

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to

Is CVE-2026-22795 actively exploited?

Active exploitation of CVE-2026-22795 has not been confirmed. The EPSS score is 0.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-22795?

CVE-2026-22795 has a CVSS v3 base score of 5.5 (MEDIUM severity), with vector string 3.1.

Is CVE-2026-22795 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.