LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-45388

Published
CVSS9.1
Severitycritical
WeaknessCWE-295
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).

References

← Back to the CVE Tracker

Our coverage of CVE-2026-45388

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-45388.