Certificate Revocation Bypass in OCSP Client from Red Hat
CVE-2026-93578

Currently unrated

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93578?

A vulnerability in the OCSP Client of Red Hat is identified, allowing attackers to bypass certificate revocation checks due to a missing Extended Key Usage (EKU) validation. This oversight can potentially lead to unauthorized access or exploitation of security certificates, raising significant concerns regarding the integrity of secure communications. Proper remediation and updates are essential to mitigate risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.