CVE-2026-42789
Erlang OTP, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key/src/pubkey_cert.erl, pubkey_cert:validate_extensions/7 contains two flaws that together allow a certificate with basicConstraints cA:false and no keyUsage extension to be used as an intermediate issuer in a chain passed to public_key:pkix_path_validation/3: the cA:false clause recurses into the remaining extensions without rejecting the certificate when it i...
- CVSS
- 7
- EPSS
- 0.33% 25.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.27