CVE-2025-66199 | OpenSSL up to 3.3.5/3.4.3/3.5.4/3.6.0 CompressedCertificate Message memory allocation (Nessus ID 297022 / WID-SEC-2026-0234)
A vulnerability was found in OpenSSL up to 3.3.5/3.4.3/3.5.4/3.6.0 and classified as problematic. Impacted is an unknown function of the component CompressedCertificate Message Handler. Executing a manipulation can lead to uncontrolled memory allocation.
This vulnerability appears as CVE-2025-66199. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.