← Vulnerability feed

Vulnerability record · CVE-2021-4044 · published 14 December 2021

CVE-2021-4044: OpenSSL libssl mishandles negative X509_verify_cert return, causing denial of service

OOpenssl · Openssl

OpenSSL 3.0.0 libssl mishandles a negative return value from X509_verify_cert() during client-side server certificate verification, causing SSL_get_error() to return the unexpected SSL_ERROR_WANT_RETRY_VERIFY. Applications that do not set SSL_CTX_set_cert_verify_callback() may crash, loop, or otherwise misbehave. Combined with a separate OpenSSL 3.0 bug that makes X509_verify_cert() report an internal error on valid chains lacking a Subject Alternative Name under enforced name constraints, an attacker can trigger this behavior remotely.

7.5 CVSS 3.1 High EPSS 50% · top 1.1% CWE-835 · CWE-835
7.5CVSS 3.1 base score, v2 5.0
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
16Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as SSL_connect() or SSL_do_handshake()) to not indicate success and a subsequent call to SSL_get_error() to return the value SSL_ERROR_WANT_RETRY_VERIFY. This return value is only supposed to be returned by OpenSSL if the application has previously called SSL_CTX_set_cert_verify_callback(). Since most applications do not do this the SSL_ERROR_WANT_RETRY_VERIFY return value from SSL_get_error() will be totally unexpected and applications may not behave correctly as a result. The exact behaviour will depend on the application but it could result in crashes, infinite loops or other similar incorrect responses. This issue is made more serious in combination with a separate bug in OpenSSL 3.0 that will cause X509_verify_cert() to indicate an internal error when processing a certificate chain. This will occur where a certificate does not include the Subject Alternative Name extension but where a Certificate Authority has enforced name constraints. This issue can occur even with valid chains. By combining the two issues an attacker could induce incorrect, application dependent behaviour. Fixed in OpenSSL 3.0.1 (Affected 3.0.0).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated denial of service with high EPSS and a CVSS of 7.5, though no confirmed exploitation or KEV listing.

What it is

OpenSSL 3.0.0 libssl mishandles a negative return value from X509_verify_cert() during client-side server certificate verification, causing SSL_get_error() to return the unexpected SSL_ERROR_WANT_RETRY_VERIFY. Applications that do not set SSL_CTX_set_cert_verify_callback() may crash, loop, or otherwise misbehave. Combined with a separate OpenSSL 3.0 bug that makes X509_verify_cert() report an internal error on valid chains lacking a Subject Alternative Name under enforced name constraints, an attacker can trigger this behavior remotely.

Impact

An attacker can induce application-dependent incorrect behavior such as crashes or infinite loops, producing a denial of service against TLS clients. No confidentiality or integrity impact is described; the CVSS vector rates availability impact as high.

Attack surface

Reached over the network via a malicious or malformed server certificate presented during the TLS handshake; the vector shows no privileges or user interaction required. The client application must be using OpenSSL 3.0.0 libssl and not have set a custom certificate verification callback.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record. EPSS is high (0.50099, 98.8th percentile), indicating elevated predicted exploitation likelihood, but the record provides no confirmed in-the-wild activity.

What to do

  • Upgrade OpenSSL to 3.0.1 or later, which fixes the issue.
  • Inventory and update downstream products bundling OpenSSL 3.0.0, including NetApp software and Node.js builds, per vendor advisories.
  • Where immediate upgrade is not possible, set SSL_CTX_set_cert_verify_callback() so the unexpected SSL_ERROR_WANT_RETRY_VERIFY return is handled explicitly.
  • Ensure client applications handle unexpected SSL_get_error() values defensively rather than assuming only documented returns.
  • Monitor vendor advisories for updated affected product versions and re-scan for OpenSSL 3.0.0 components.

Detection

  • Search hosts and container images for OpenSSL 3.0.0 libraries and linked applications.
  • Monitor TLS client processes for abnormal crashes, hangs, or infinite loops during handshake with external servers.
  • Log and alert on SSL_ERROR_WANT_RETRY_VERIFY occurrences in application logs where the callback was not configured.
  • Correlate outbound TLS connection failures with servers presenting certificate chains lacking Subject Alternative Name under name constraints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-4044 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed8.4CVE-2022-0185Linux Kernel Filesystem Context Heap Buffer OverflowThe legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a…KEVEPSS 25%analysed7.8CVE-2024-1086Linux kernel nf_tables use-after-free allows local privilege escalationThe Linux kernel's netfilter nf_tables component has a use-after-free in nft_verdict_init(), where positive drop errors are accepted and nf_hook_slow…KEVEPSS 28%analysed7.8CVE-2022-0995Linux kernel watch_queue out-of-bounds writeThe Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user c…KEVEPSS 8.8%analysed7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed7.8CVE-2021-22555Linux kernel netfilter x_tables heap out-of-bounds writeA heap out-of-bounds write exists in the Linux kernel netfilter x_tables code (net/netfilter/x_tables.c), present since v2.6.19-rc1. A local attacker…KEVEPSS 79%analysed

Source: NIST National Vulnerability Database (record CVE-2021-4044), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.