DevSecOps Toolkit

CVE record

CVE-2026-42508

UNKNOWN

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

Vulnerability metadata

Published
2026-05-21T22:46:25.440Z
Modified
2026-05-21T22:46:25.440Z
EPSS
Not available
Vector
Not available

References