CVE-2026-4428 Details
Description
A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.
A logic error has been identified in AWS-LC versions 1.24.0 prior to 1.71.0 and in AWS-LC-FIPS versions 3.0.0 prior to 3.3.0. This vulnerability affects the validation of Certificate Revocation Lists (CRLs) in X.509 certificate verification. When CRL checking is enabled, partitioned CRLs with Issuing Distribution Point (IDP) extensions can incorrectly reject revoked certificates as out of scope, allowing them to bypass revocation checks. Applications not using CRL checking or those relying on complete, non-partitioned CRLs without IDP extensions are not affected.
Users should upgrade to AWS-LC version 1.71.0, AWS-LC-FIPS version 3.3.0, aws-lc-sys version 0.39.0, or aws-lc-fips-sys version 0.13.13. For applications using forked or derivative code, ensure to incorporate these updates. Instructions for downloading the latest version are available on the AWS-LC GitHub release page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-010-AWS/ | AMZN | |
| https://github.com/aws/aws-lc/releases/tag/v1.71.0 | AMZN |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-299 | Improper Check for Certificate Revocation | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 19, 2026 | New CVE Received | AMZN |