CVE-2026-45389

HIGH

OCaml-TLS < 2.1.0 - Client Certificate Impersonation via Insufficient KeyUsage Validation

Title source: llm
STIX 2.1

Description

In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage).

References (1)

Core 1

Scores

CVSS v3 7.4
EPSS 0.0019
EPSS Percentile 9.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Published Jun 15, 2026
Tracked Since Jun 16, 2026