CVE-2026-4428
A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-299
- Published
- 2026-03-19
- Last modified
- 2026-03-25
Affected products
- AWS AWS-LC
- AWS AWS-LC-FIPS
Weakness type
Related vulnerabilities
- CVE-2026-86231 — mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
- CVE-2026-61699 — nebula-mesh: Certificate revocation is never enforced at the mesh
- CVE-2026-56821 — Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
- CVE-2026-9636 — Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module – Certificate Revocation List Vulnerability
- CVE-2026-6899 — Improper Check for Certificate Revocation in S2OPC
- CVE-2025-11955 — Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
- CVE-2025-36057 — IBM Cognos Analytics Mobile (iOS) authentication bypass
- CVE-2025-3085 — MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked