# CVE-2026-4428

## Summary

- **CVE ID:** CVE-2026-4428
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-299
- **Published:** Mar 19, 2026
- **Last Modified:** Mar 25, 2026

## Description

A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows  a revoked certificate to bypass certificate revocation checks.

To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.

## Affected Products

- AWS — AWS-LC (1.24.0)
- AWS — AWS-LC-FIPS (3.0.0)

## References

- [CNA](https://aws.amazon.com/security/security-bulletins/2026-010-AWS/)
- [CNA](https://github.com/aws/aws-lc/releases/tag/v1.71.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 16.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._