What is CVE-2026-54876?
CVE-2026-54876 is a memory leak vulnerability in TLS clients with OCSP response checking enabled, triggered by a malicious TLS server sending an OCSP response with no single response entries. This flaw allows an attacker to leak a tunable amount of memory per TLS handshake from the victim client. Affected users should disable OCSP checking or apply security patches to mitigate the risk.
Azərbaycanca: CVE-2026-54876, TLS müştərilərində OCSP cavab yoxlaması aktiv olduqda, zərərli TLS serveri tərəfindən göndərilən boş OCSP cavabı səbəbindən yaranan yaddaş sızması zəifliyidir. Bu zəiflik, hər TLS əl sıxışmasında təcavüzkar tərəfindən idarə oluna bilən yaddaş miqdarının sızdırılmasına imkan verir. Təsirə məruz qalan müştərilər OCSP yoxlamasını deaktiv etməli və ya müvafiq təhlükəsizlik yeniləmələrini tətbiq etməlidir.
FAQ1
What does the CVE-2026-54876 vulnerability lead to in TLS clients with OCSP response checking enabled?
This flaw allows an attacker to leak a tunable amount of memory per TLS handshake.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.