Vulnerabilities 1seal found, reported and wrote up in full. Each write-up keeps its original date and wording; dated updates are marked.
10 advisories, newest first by original publication. Summaries reviewed 2026-09-25 against the records each write-up links. Source assessments remain separate; different CVSS versions are not a revision of one another.
Parsing an untrusted firmware image can reach out-of-bounds writes in MakeTable or ReadCLen.
What to do
Check the installed package for the linked Tiano bounds checks. Release metadata conflicts: CVE records name 1.14; repository advisories name 1.13. Do not resolve that discrepancy from the version number alone.
Fix and severity by source
1sealseverity Critical · no scoreFix / version: CVE records: 1.14; repository GHSAs: 1.13 (conflicting version metadata)
OpenSSL 3.6 stapled OCSP verification can accept a response from an unauthorized certificate supplied in the peer chain.
What to do
Check that your build includes the recorded master or openssl-3.6 fix. A released version is not established by this write-up; PR #30323 itself was closed without merge.
Fix and severity by source
1sealseverity High · no scoreFix / version: master and openssl-3.6 fixes published
A wildcard or Unicode CommonName can bypass name constraints when hostname verification falls back to CN without a DNS name SAN.
What to do
Check the package-specific AWS advisories for fixed versions. Disabling CN fallback avoids this path; do not apply the AWS-LC version number to aws-lc-sys.
A tenant able to create requests using the git resolver can read files accessible to the resolver pod, including its credentials.
What to do
Use the listed patched release for your branch. Until updated, restrict access to the git resolver and reduce its service-account permissions. The upstream broad affected range overlaps its own patched list.
A malicious host interacting with the signing flow can bypass a reported Merkle preimage integrity check.
What to do
Check for the recorded commit in the app build you use. No fixed app release is recorded here; a code fix is not proof that your device has received it.
Fix and severity by source
1sealseverity High · no scoreFix / version: commit 0586ab2
A client processing attacker-controlled event-stream headers can reach an out-of-bounds write in the streaming decoder.
What to do
Upgrade aws-c-event-stream to v0.6.0 or later and affected AWS SDK for C++ builds to the vendor's fixed version below. Check lock files as well: the AWS Common Runtime can pin an older version as a transitive dependency.
Every public record, including CVEs, GHSAs and fixes without a 1seal write-up, is in the research record. How we report and publish: disclosure policy.