{"schema_version":"1.9.0","id":"CVE-2026-31789","published":"2026-04-07T22:00:54.983Z","modified":"2026-08-12T15:32:18.662596Z","related":["CGA-rg85-h2qj-w6x6","SUSE-SU-2026:1213-1","SUSE-SU-2026:1214-1","SUSE-SU-2026:1215-1","SUSE-SU-2026:1216-1","SUSE-SU-2026:1255-1","SUSE-SU-2026:1256-1","SUSE-SU-2026:1257-1","SUSE-SU-2026:1290-1","SUSE-SU-2026:1291-1","SUSE-SU-2026:1375-1","SUSE-SU-2026:1386-1","SUSE-SU-2026:1577-1","SUSE-SU-2026:21037-1","SUSE-SU-2026:21065-1","SUSE-SU-2026:21107-1","SUSE-SU-2026:21186-1","openSUSE-SU-2026:10533-1","openSUSE-SU-2026:20525-1"],"summary":"Heap Buffer Overflow in Hexadecimal Conversion","details":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"89cd17a031e022211684eb7eb41190cf1910f9fa"},{"fixed":"5aada9c299a3b28fc82348f4e2b93805fa0a0e9c"},{"introduced":"4cb31128b5790819dfeea2739fbde265f71a10a2"},{"fixed":"204165c1550d3aa0f49395af654124cec2bbabf9"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"03b8620d6e9b7b4d5701865edb6ad86101fe5517"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"fixed":"286ddeaac037533bbdce65b3c689e3f7ffebf0f6"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"fixed":"fe686e15d84334b284f883118ed92f64b409b3aa"},{"fixed":"364f095b80601db632b0def6a33316967f863bde"},{"fixed":"7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"},{"fixed":"945b935ac66cc7f1a41f1b849c7c25adb5351f49"},{"fixed":"a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"},{"fixed":"a91e537d16d74050dbde50bb0dfb1fe9930f0521"}],"database_specific":{"cpe":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.20"},{"introduced":"3.3.0"},{"fixed":"3.3.7"},{"introduced":"3.4.0"},{"fixed":"3.4.5"},{"introduced":"3.5.0"},{"fixed":"3.5.6"},{"introduced":"3.6.0"},{"fixed":"3.6.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["openssl-3.0.19","openssl-3.3.6","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.0-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.3-POST-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.0-PRE-CLANG-FORMAT-WEBKIT","3.3-PRE-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.0.18","openssl-3.3.5","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.0.17","openssl-3.3.4","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.0.16","openssl-3.3.3","openssl-3.4.1","openssl-3.4.0","openssl-3.0.15","openssl-3.3.2","openssl-3.0.14","openssl-3.3.1","openssl-3.3.0","openssl-3.0.13","openssl-3.0.12","openssl-3.0.11","openssl-3.0.10","openssl-3.0.9","openssl-3.0.8","openssl-3.0.7","openssl-3.0.6","openssl-3.0.5","openssl-3.0.4","openssl-3.0.3","openssl-3.0.2","openssl-3.0.1","openssl-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31789.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["329382961734959197819209899534623993468","55374998995788269249827066906226581278","133376494664120063749579942137121853857","82850511474788103760666898981665479970","293676623172674133991091961579462176743","94441155123678812067076334544561964750","32981005760341672806188573898894715648"],"threshold":0.9},"id":"CVE-2026-31789-039277ee","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","target":{"file":"crypto/o_str.c"}},{"deprecated":false,"digest":{"function_hash":"310899379422657902742420251421577806881","length":369},"id":"CVE-2026-31789-1e19457d","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","target":{"file":"crypto/o_str.c","function":"ossl_buf2hexstr_sep"}},{"deprecated":false,"digest":{"line_hashes":["172423477058269526725656722050429632732","12041271885289980789323921232065527265","327130240091732231224050154786201163088","82850511474788103760666898981665479970","293676623172674133991091961579462176743","94441155123678812067076334544561964750","32981005760341672806188573898894715648"],"threshold":0.9},"id":"CVE-2026-31789-25909487","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","target":{"file":"crypto/o_str.c"}},{"deprecated":false,"digest":{"function_hash":"310899379422657902742420251421577806881","length":369},"id":"CVE-2026-31789-3657b2bc","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","target":{"file":"crypto/o_str.c","function":"ossl_buf2hexstr_sep"}},{"deprecated":false,"digest":{"function_hash":"14680270826734405925978932024469817197","length":831},"id":"CVE-2026-31789-41bcda54","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","target":{"file":"crypto/o_str.c","function":"buf2hexstr_sep"}},{"deprecated":false,"digest":{"function_hash":"14680270826734405925978932024469817197","length":831},"id":"CVE-2026-31789-6a58f556","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","target":{"file":"crypto/o_str.c","function":"buf2hexstr_sep"}},{"deprecated":false,"digest":{"function_hash":"152217791859938781845437568088725852880","length":690},"id":"CVE-2026-31789-6bb53427","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","target":{"file":"crypto/o_str.c","function":"buf2hexstr_sep"}},{"deprecated":false,"digest":{"function_hash":"310899379422657902742420251421577806881","length":369},"id":"CVE-2026-31789-6fa0e124","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","target":{"file":"crypto/o_str.c","function":"ossl_buf2hexstr_sep"}},{"deprecated":false,"digest":{"function_hash":"152217791859938781845437568088725852880","length":690},"id":"CVE-2026-31789-7ac11e73","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","target":{"file":"crypto/o_str.c","function":"buf2hexstr_sep"}},{"deprecated":false,"digest":{"line_hashes":["329382961734959197819209899534623993468","55374998995788269249827066906226581278","133376494664120063749579942137121853857","58955271873742165645176256274849197273","308928382765541429048570142868762583429","82850511474788103760666898981665479970","145768704303235810735817478209763365430","202253481900009397289368256494304740244","83296124437168484301867924454523249870"],"threshold":0.9},"id":"CVE-2026-31789-96e63b8a","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","target":{"file":"crypto/o_str.c"}},{"deprecated":false,"digest":{"function_hash":"152217791859938781845437568088725852880","length":690},"id":"CVE-2026-31789-9d37d242","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","target":{"file":"crypto/o_str.c","function":"buf2hexstr_sep"}},{"deprecated":false,"digest":{"line_hashes":["172423477058269526725656722050429632732","12041271885289980789323921232065527265","327130240091732231224050154786201163088","82850511474788103760666898981665479970","293676623172674133991091961579462176743","94441155123678812067076334544561964750","32981005760341672806188573898894715648"],"threshold":0.9},"id":"CVE-2026-31789-b821ddb5","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","target":{"file":"crypto/o_str.c"}},{"deprecated":false,"digest":{"function_hash":"310899379422657902742420251421577806881","length":369},"id":"CVE-2026-31789-b8fd89e2","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","target":{"file":"crypto/o_str.c","function":"ossl_buf2hexstr_sep"}},{"deprecated":false,"digest":{"function_hash":"339467807135829078326902270695315446745","length":426},"id":"CVE-2026-31789-c468f6f3","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","target":{"file":"crypto/o_str.c","function":"ossl_buf2hexstr_sep"}},{"deprecated":false,"digest":{"line_hashes":["172423477058269526725656722050429632732","12041271885289980789323921232065527265","327130240091732231224050154786201163088","82850511474788103760666898981665479970","293676623172674133991091961579462176743","94441155123678812067076334544561964750","32981005760341672806188573898894715648"],"threshold":0.9},"id":"CVE-2026-31789-ca3ec814","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","target":{"file":"crypto/o_str.c"}}],"vanir_signatures_modified":"2026-08-12T15:32:18Z"}}],"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31789.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260407.txt"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521"}],"database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31789.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"}]}