VYPR
Unrated severityNVD Advisory· Published Mar 19, 2026· Updated Mar 25, 2026

CRL Distribution Point Scope Check Logic Error in AWS-LC

CVE-2026-4428

Description

A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks.

To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.

Affected products

3
  • Aws/AWS-LCllm-create
    Range: <1.71.0
  • AWS/AWS-LCv5
    Range: 1.24.0
  • AWS/AWS-LC-FIPSv5
    Range: 3.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.