aws.amazon.comVendor advisory
https://aws.amazon.com/security/security-bulletins/2026-010-AWS CVE-2026-4428
CRITICAL
CRL Distribution Point Scope Check Logic Error in AWS-LC
Record summary
CVE-2026-4428 has a selected CVSS score of 9.1 (critical).
Description
A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
AWS-LCBrowse AWS / AWS-LCDefault status: unaffected | CVE List | 1.24.0 to < 1.71.0 | affected |
AWS-LC-FIPSBrowse AWS / AWS-LC-FIPSDefault status: unaffected | CVE List | 3.0.0 to < 3.3.0 | affected |
References
2github.compatch
https://github.com/aws/aws-lc/releases/tag/v1.71.0