Root cause, affected code and disclosure timeline.
At a glance
Conditions
OpenSSL 3.6 stapled OCSP verification can accept a response from an unauthorized certificate supplied in the peer chain.
What to do
Check that your build includes the recorded master or openssl-3.6 fix. A released version is not established by this write-up; PR #30323 itself was closed without merge.
1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.
Fix / version: master and openssl-3.6 fixes published Severity: high; numeric score not recorded
Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.
A response signature can validate while the signer is not authorized to answer for the certificate. The reported gap concerns OpenSSL 3.6 stapled OCSP verification.
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.