A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks.
To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4428.json",
"cwe_ids": [
"CWE-299"
],
"cna_assigner": "AMZN"
}[
{
"id": "CVE-2026-4428-4fef2854",
"target": {
"function": "crl_crldp_check",
"file": "crypto/x509/x509_vfy.c"
},
"deprecated": false,
"digest": {
"function_hash": "315553051490645340434301782701760588989",
"length": 621.0
},
"signature_version": "v1",
"source": "https://github.com/aws/aws-lc/commit/83d85826595641bb2f23c6108f2e031fcd5cd505",
"signature_type": "Function"
},
{
"id": "CVE-2026-4428-858c9e2d",
"target": {
"file": "crypto/x509/x509_test.cc"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"67546155362554212794720633293763579087",
"60173126581954837125601684341052211646",
"171474131814531793932529892352574222281",
"179823018402105157128282776881034288750",
"126559276406436210284828049326390844784",
"67089962090722491870780077947163980547"
]
},
"signature_version": "v1",
"source": "https://github.com/aws/aws-lc/commit/83d85826595641bb2f23c6108f2e031fcd5cd505",
"signature_type": "Line"
},
{
"id": "CVE-2026-4428-a4bd71ac",
"target": {
"file": "crypto/x509/x509_vfy.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"211160966742197397106823759224917572755",
"35047788452717782869365276537476936",
"280559450770590975653021767826529623376",
"153990721801522824870147534967993801522",
"27068015445326099177373872550785267766",
"217631864836764034369360838167683719714",
"196990455326174579627504348853721303576",
"152716710549071912863749139833951271141",
"230925751211779502697051772006460993554",
"90797013554136129170406954188265437728",
"186246592097486328349711158695014349986"
]
},
"signature_version": "v1",
"source": "https://github.com/aws/aws-lc/commit/47389586f8aa77c83245173793f4d44ed1d6c3a8",
"signature_type": "Line"
},
{
"id": "CVE-2026-4428-aa813e60",
"target": {
"file": "crypto/x509/x509_vfy.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"211160966742197397106823759224917572755",
"35047788452717782869365276537476936",
"280559450770590975653021767826529623376",
"153990721801522824870147534967993801522",
"27068015445326099177373872550785267766",
"217631864836764034369360838167683719714",
"196990455326174579627504348853721303576",
"152716710549071912863749139833951271141",
"230925751211779502697051772006460993554",
"90797013554136129170406954188265437728",
"186246592097486328349711158695014349986"
]
},
"signature_version": "v1",
"source": "https://github.com/aws/aws-lc/commit/83d85826595641bb2f23c6108f2e031fcd5cd505",
"signature_type": "Line"
},
{
"id": "CVE-2026-4428-cb29f789",
"target": {
"function": "crl_crldp_check",
"file": "crypto/x509/x509_vfy.c"
},
"deprecated": false,
"digest": {
"function_hash": "315553051490645340434301782701760588989",
"length": 621.0
},
"signature_version": "v1",
"source": "https://github.com/aws/aws-lc/commit/47389586f8aa77c83245173793f4d44ed1d6c3a8",
"signature_type": "Function"
},
{
"id": "CVE-2026-4428-e2336e74",
"target": {
"file": "crypto/x509/x509_test.cc"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"67546155362554212794720633293763579087",
"60173126581954837125601684341052211646",
"171474131814531793932529892352574222281",
"179823018402105157128282776881034288750",
"126559276406436210284828049326390844784",
"67089962090722491870780077947163980547"
]
},
"signature_version": "v1",
"source": "https://github.com/aws/aws-lc/commit/47389586f8aa77c83245173793f4d44ed1d6c3a8",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4428.json"
"2026-08-12T16:24:28Z"