CVE-2026-45388

CRITICAL

OCaml-TLS < 2.1.0 - Certificate Validation Bypass via Insufficient KeyUsage Checks

Title source: llm
STIX 2.1

Description

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0022
EPSS Percentile 13.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-295
Status published
Published Jun 15, 2026
Tracked Since Jun 16, 2026