A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks.
To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.
{
"cwe_ids": [
"CWE-299"
],
"cna_assigner": "AMZN",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4428.json"
}"2026-08-12T16:24:28Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4428.json"
[
{
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 621.0,
"function_hash": "315553051490645340434301782701760588989"
},
"id": "CVE-2026-4428-4fef2854",
"source": "https://github.com/aws/aws-lc/commit/83d85826595641bb2f23c6108f2e031fcd5cd505",
"target": {
"function": "crl_crldp_check",
"file": "crypto/x509/x509_vfy.c"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"67546155362554212794720633293763579087",
"60173126581954837125601684341052211646",
"171474131814531793932529892352574222281",
"179823018402105157128282776881034288750",
"126559276406436210284828049326390844784",
"67089962090722491870780077947163980547"
],
"threshold": 0.9
},
"id": "CVE-2026-4428-858c9e2d",
"source": "https://github.com/aws/aws-lc/commit/83d85826595641bb2f23c6108f2e031fcd5cd505",
"target": {
"file": "crypto/x509/x509_test.cc"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"211160966742197397106823759224917572755",
"35047788452717782869365276537476936",
"280559450770590975653021767826529623376",
"153990721801522824870147534967993801522",
"27068015445326099177373872550785267766",
"217631864836764034369360838167683719714",
"196990455326174579627504348853721303576",
"152716710549071912863749139833951271141",
"230925751211779502697051772006460993554",
"90797013554136129170406954188265437728",
"186246592097486328349711158695014349986"
],
"threshold": 0.9
},
"id": "CVE-2026-4428-a4bd71ac",
"source": "https://github.com/aws/aws-lc/commit/47389586f8aa77c83245173793f4d44ed1d6c3a8",
"target": {
"file": "crypto/x509/x509_vfy.c"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"211160966742197397106823759224917572755",
"35047788452717782869365276537476936",
"280559450770590975653021767826529623376",
"153990721801522824870147534967993801522",
"27068015445326099177373872550785267766",
"217631864836764034369360838167683719714",
"196990455326174579627504348853721303576",
"152716710549071912863749139833951271141",
"230925751211779502697051772006460993554",
"90797013554136129170406954188265437728",
"186246592097486328349711158695014349986"
],
"threshold": 0.9
},
"id": "CVE-2026-4428-aa813e60",
"source": "https://github.com/aws/aws-lc/commit/83d85826595641bb2f23c6108f2e031fcd5cd505",
"target": {
"file": "crypto/x509/x509_vfy.c"
}
},
{
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 621.0,
"function_hash": "315553051490645340434301782701760588989"
},
"id": "CVE-2026-4428-cb29f789",
"source": "https://github.com/aws/aws-lc/commit/47389586f8aa77c83245173793f4d44ed1d6c3a8",
"target": {
"function": "crl_crldp_check",
"file": "crypto/x509/x509_vfy.c"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"67546155362554212794720633293763579087",
"60173126581954837125601684341052211646",
"171474131814531793932529892352574222281",
"179823018402105157128282776881034288750",
"126559276406436210284828049326390844784",
"67089962090722491870780077947163980547"
],
"threshold": 0.9
},
"id": "CVE-2026-4428-e2336e74",
"source": "https://github.com/aws/aws-lc/commit/47389586f8aa77c83245173793f4d44ed1d6c3a8",
"target": {
"file": "crypto/x509/x509_test.cc"
}
}
]