216.73.217.22

CVE-2026-4428

· Published 19/03/2026 21:17 · Modified 20/03/2026 13:39

Labels: CVE-2026-4428 2026-03-19CVE-2026-4428CWE-299ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
19/03/2026 21:17
Modified
20/03/2026 13:39
Author
Creator
CVSS
9.1 CRITICAL (v3) 9.1 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

Affected products (CPE)

ProductCPE
aws / aws-lc cpe:2.3:a:aws:aws-lc:*:*:*:*:*:*:*:*
aws / aws-lc-fips cpe:2.3:a:aws:aws-lc-fips:*:*:*:*:*:*:*:*

References