Back to overview

CVE-2026-45389

Description
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage).

Metadata

CVE ID
CVE-2026-45389
State
PUBLISHED
Assigner
mitre
Reserved
2026-05-12 00:00 UTC
Published
2026-06-15 00:00 UTC
Last updated
2026-06-15 18:52 UTC
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
Back to overview