CVE-2026-32144
Erlang OTP, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP response validation in public_key:pkix_ocsp_validate/5 does not verify that a CA-designated responder certificate was cryptographically signed by the issuing CA. Instead, it only checks that the responder certificate's issuer name matches the CA's subject name and that the certificate has the OCSPSigning extended key usage. An attacker who can intercept or control OCSP responses can create a self-signed...
- CVSS
- 7.6
- EPSS
- 0.20% 9.99% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.07