In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage).
References
| Link | Resource |
|---|---|
| https://osv.dev/vulnerability/OSEC-2026-07 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-15 20:16
Updated : 2026-06-17 17:17
NVD link : CVE-2026-45389
Mitre link : CVE-2026-45389
CVE.ORG link : CVE-2026-45389
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation
