Количество 3
Количество 3
CVE-2026-45389
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage).
CVE-2026-45389
In OCaml-TLS before 2.1.0, the server implementation does insufficient ...
GHSA-8wf9-g5q8-gg97
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-45389 In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage). | CVSS3: 7.4 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-45389 In OCaml-TLS before 2.1.0, the server implementation does insufficient ... | CVSS3: 7.4 | 0% Низкий | около 2 месяцев назад | |
GHSA-8wf9-g5q8-gg97 In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage). | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу