Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33753

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic flaw in how the library extracts the leaf certificate from an unordered PKCS#7 bag of certificates, an attacker can append a spoofed certificate matching the target common_name and Extended Key Usage (EKU) requirements. This tricks the library into verifying these authorization rules against the forged certificate while validating the cryptographic signature against an actual trusted TSA (such as FreeTSA), thereby bypassing the intended TSA authorization pinning entirely. This vulnerability is fixed in 1.0.6.

A flaw was found in rfc3161-client, a Python library implementing the Time-Stamp Protocol (TSP). This authorization bypass vulnerability allows a remote attacker to impersonate a trusted TimeStamping Authority (TSA). The flaw exists in the library's signature verification process, specifically in how it extracts certificates from a PKCS#7 bag (a standard for cryptographic messages). An attacker can exploit a logic error to present a forged certificate, leading the library to incorrectly validate authorization rules and bypass intended TSA authorization pinning.

Отчет

This vulnerability has a Moderate impact. A flaw in the rfc3161-client library, used by Red Hat Trusted Artifact Signer, allows an attacker to bypass authorization and impersonate a trusted TimeStamping Authority. This is due to a logic error in how the library extracts certificates during signature verification, enabling the use of a forged certificate to bypass TSA authorization pinning. As a consequence of a successful attack applications relying in rfc3161-client to validate the origin of a timestamp are exposed to impersonation, causing a high impact in the integrity of the data related to the validation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Trusted Artifact Signersecuresign/model-transparencyOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2456545rfc3161-client: rfc3161-client: Authorization bypass allows impersonation of TimeStamping Authority

EPSS

Процентиль: 9%
0.00188
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
4 месяца назад

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic flaw in how the library extracts the leaf certificate from an unordered PKCS#7 bag of certificates, an attacker can append a spoofed certificate matching the target common_name and Extended Key Usage (EKU) requirements. This tricks the library into verifying these authorization rules against the forged certificate while validating the cryptographic signature against an actual trusted TSA (such as FreeTSA), thereby bypassing the intended TSA authorization pinning entirely. This vulnerability is fixed in 1.0.6.

CVSS3: 6.2
debian
4 месяца назад

rfc3161-client is a Python library implementing the Time-Stamp Protoco ...

CVSS3: 6.2
github
4 месяца назад

rfc3161-client Has Improper Certificate Validation

EPSS

Процентиль: 9%
0.00188
Низкий

6.2 Medium

CVSS3