{"api_version":"1","generated_at":"2026-09-01T02:38:39+00:00","cve":"CVE-2026-75803","urls":{"html":"https://cve.report/CVE-2026-75803","api":"https://cve.report/api/cve/CVE-2026-75803.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-75803","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803"},"summary":{"title":"AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.","state":"PUBLISHED","assigner":"openssl","published_at":"2026-08-25 13:19:29","updated_at":"2026-08-28 19:46:29"},"problem_types":["CWE-354","CWE-354 Improper Validation of Integrity Check Value"],"metrics":[],"references":[{"url":"https://openssl-library.org/news/secadv/20260825.txt","name":"https://openssl-library.org/news/secadv/20260825.txt","refsource":"openssl-security@openssl.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","name":"https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","refsource":"openssl-security@openssl.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","name":"https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","refsource":"openssl-security@openssl.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","name":"https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","refsource":"openssl-security@openssl.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","name":"https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","refsource":"openssl-security@openssl.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","name":"https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","refsource":"openssl-security@openssl.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-75803","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"OpenSSL","product":"OpenSSL","version":"affected 4.0.0 4.0.2 semver","platforms":[]},{"source":"CNA","vendor":"OpenSSL","product":"OpenSSL","version":"affected 3.6.0 3.6.4 semver","platforms":[]},{"source":"CNA","vendor":"OpenSSL","product":"OpenSSL","version":"affected 3.5.0 3.5.8 semver","platforms":[]},{"source":"CNA","vendor":"OpenSSL","product":"OpenSSL","version":"affected 3.4.0 3.4.7 semver","platforms":[]},{"source":"CNA","vendor":"OpenSSL","product":"OpenSSL","version":"affected 3.0.0 3.0.22 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Billy Brumley (Rochester Institute of Technology)","lang":"en"},{"source":"CNA","value":"Billy Brumley (Rochester Institute of Technology)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"75803","cve":"CVE-2026-75803","epss":"0.001160000","percentile":"0.017920000","score_date":"2026-08-30","updated_at":"2026-08-31 00:14:04"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"OpenSSL","vendor":"OpenSSL","versions":[{"lessThan":"4.0.2","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"3.6.4","status":"affected","version":"3.6.0","versionType":"semver"},{"lessThan":"3.5.8","status":"affected","version":"3.5.0","versionType":"semver"},{"lessThan":"3.4.7","status":"affected","version":"3.4.0","versionType":"semver"},{"lessThan":"3.0.22","status":"affected","version":"3.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Billy Brumley (Rochester Institute of Technology)"},{"lang":"en","type":"remediation developer","value":"Billy Brumley (Rochester Institute of Technology)"}],"datePublic":"2026-08-25T15:57:42.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty<br>ciphertext can report success without verifying the supplied authentication<br>tag when the operation is finalized by calling the EVP_Cipher() function.<br><br>Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and<br>expecting the call to check the AEAD tag may accept forged messages.<br><br>CWE: CWE-354 (Improper Validation of Integrity Check Value)<br><br>Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one<br>shot encryption and decryption call. It also verifies the AEAD tag after the<br>decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers<br>it skipped the AEAD tag verification when an empty ciphertext was passed to<br>the function. The callers of this function might believe that a successful<br>return indicates a valid AEAD tag for these ciphers, even when that has not<br>truly been validated in this case.<br><br>FIPS impact: no<br>The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE<br>as the affected algorithms are not FIPS approved and thus not implemented<br>in the FIPS module."}],"value":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}],"metrics":[{"format":"other","other":{"content":{"text":"Low"},"type":"https://openssl-library.org/policies/general/security-policy/"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-354","description":"Improper Validation of Integrity Check Value","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-25T13:00:25.067Z","orgId":"3a12439a-ef3a-4c79-92e6-6081a721f1e5","shortName":"openssl"},"references":[{"name":"OpenSSL Advisory","tags":["vendor-advisory"],"url":"https://openssl-library.org/news/secadv/20260825.txt"},{"name":"4.0.2 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a"},{"name":"3.6.4 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b"},{"name":"3.5.8 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34"},{"name":"3.4.7 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9"},{"name":"3.0.22 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42"}],"source":{"discovery":"UNKNOWN"},"title":"AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"3a12439a-ef3a-4c79-92e6-6081a721f1e5","assignerShortName":"openssl","cveId":"CVE-2026-75803","datePublished":"2026-08-25T13:00:25.067Z","dateReserved":"2026-08-18T09:34:32.659Z","dateUpdated":"2026-08-25T13:00:25.067Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-25 13:19:29","lastModifiedDate":"2026-08-28 19:46:29","problem_types":["CWE-354","CWE-354 Improper Validation of Integrity Check Value"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"75803","Ordinal":"1","Title":"AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()","CVE":"CVE-2026-75803","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"75803","Ordinal":"1","NoteData":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.","Type":"Description","Title":"AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()"}]}}}