CVE-2026-4428

7.4 HIGH
Published: March 19, 2026 Modified: March 19, 2026
View on NVD

Description

A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://aws.amazon.com/security/security-bulletins/2026-010-AWS/
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
https://github.com/aws/aws-lc/releases/tag/v1.71.0
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5

2 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.4 / 10.0
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)