Logic Error in Certificate Revocation Validation in AWS-LC by Amazon Web Services
CVE-2026-4428

9.1CRITICAL

Key Information:

Vendor

Aws

Vendor
CVE Published:
19 March 2026

What is CVE-2026-4428?

A logic error in the certificate revocation list (CRL) distribution point validation in AWS-LC versions prior to 1.71.0 can lead to revoked certificates being incorrectly accepted, as partitioned CRLs may be rejected as out of scope. This issue allows potentially harmful certificates to bypass standard revocation checks, posing security risks to applications using the affected product. Users are advised to upgrade to AWS-LC version 1.71.0 or AWS-LC-FIPS version 3.3.0 to address this vulnerability effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AWS-LC 1.24.0 < 1.71.0

AWS-LC-FIPS 3.0.0 < 3.3.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.