CVE-2026-32144
Erlang OTP, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1 취약점
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP response validation in public_key:pkix_ocsp_validate/5 does not verify that a CA-designated responder certificate was cryptographically signed by the issuing CA. Instead, it only checks that the responder certificate's issuer name matches the CA's subject name and that the certificate has the OCSPSigning extended key usage. An attacker who can intercept or control OCSP responses can create a self-signed...
- 대응 우선순위
- 점검
- CVSS
- 7.6
- EPSS
- 0.20% 백분위 9.99% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.07