Skip to content

CVE lookup

CVE-2026-17510

Pruva has a verified reproduction for CVE-2026-17510: Crypt::OpenSSL::PKCS12 before 1.98 can crash with a NULL pointer dereference when `info_as_hash()` parses a crafted PKCS#12 containing a zero-length BMPSTRING attribute.. The canonical evidence record is REPRO-2026-00333.

REPRO

REPRO-2026-00333

Package

dsully/perl-crypt-openssl-pkcs12 · CPAN

Severity

MEDIUM

Status

published