CVE-2026-57225

critical

Description

The vulnerability exists due to flawed recursion tracking during the disassembly of heavily nested ASN.1 structures used in cryptographic handshakes. By flooding the network monitor with complex, multi-layered identity fields, an attacker can intentionally exhaust the execution stack frame.

Details

Source: Mitre, NVD

Published: 2026-07-23

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical