CVE-2026-10303

7.4 HIGH
Published: June 16, 2026 Modified: June 16, 2026
View on NVD

Description

In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used in challenge-file handling, allowing a maliciously crafted token to influence local path/filename usage during validation. An attacker who can supply ACME challenge responses to getssl (for example, a malicious or compromised CA endpoint, or an on-path adversary able to tamper with that response path) could exploit this to achieve unauthorized file write/path traversal effects, usually with elevated privileges, ultimately allowing for remote command injection. This issue appears related in spirit to CVE-2023-38198, and is an instance of CWE-73, "External control of file name or path." Other ACME shell script handlers may be affected by similar issues.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/srvrco/getssl/pull/896
Source: 44488dab-36db-4358-99f9-bc116477f914
https://github.com/srvrco/getssl/releases/tag/v2.50
Source: 44488dab-36db-4358-99f9-bc116477f914
https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/
Source: 44488dab-36db-4358-99f9-bc116477f914
https://www.cve.org/CVERecord?id=CVE-2023-38198
Source: 44488dab-36db-4358-99f9-bc116477f914

5 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.4 / 10.0
EPSS (Exploit Probability)
0.8%
50th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)