在启用 宏的情况下, 函数为了降低峰值内存占用,将证书签名验证与解析过程分离执行,然后再合并两者的结果。然而,该函数仅在解析成功(返回 0)时才合并签名验证结果,因此任何解析错误都会掩盖签名验证失败的结果。 此外, 函数仅在 验证通过之后,才会执行日期有效性、名称约束和关键扩展检查。这种将签名验证分离的做法,颠倒了原本使“覆盖日期错误”成为合理策略的执行顺序,导致 错误码无法在任何地方被正确上报。 攻击者无需从真实公钥基础设施(PKI)获取任何密钥材料,也无需 compromise(攻破)证书颁发机构(CA)。攻击
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93302 | 8.3 HIGH | Trusted peer certificate match ignores public key, allowing forged CA clones |
| CVE-2026-89136 | 8.3 HIGH | Client accepts unsolicited RawPublicKey server certificate type |
| CVE-2026-89102 | 8.3 HIGH | OCSP stapling v2 multi accepts non-CA chain certificates as issuers |
| CVE-2026-93304 | 6.3 MEDIUM | (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange |
| CVE-2026-89133 | 6.3 MEDIUM | NameConstraints not enforced across unconstrained intermediate CA |
| CVE-2026-89134 | 6.3 MEDIUM | Subject CN name-constraint check bypassed when non-DNS SAN present |
| CVE-2026-89135 | 6.3 MEDIUM | Failed X509_verify_cert leaves unverified CA in shared CertManager |
| CVE-2026-15442 | 2.3 LOW | Heap use-after-free on read during bidirectional (D)TLS shutdown |
| CVE-2026-94419 | 2.3 LOW | Client session cache reference poisoning allows resumption with wrong server |
| CVE-2026-94417 | 2.3 LOW | CRL check skipped when OCSP enabled and certificate has no OCSP URL |
No comments yet