Off-by-one in LibreSSL - #VU153350
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause incorrect enforcement of certificate-chain depth limits.
The vulnerability exists due to an off-by-one error in the X.509 verifier depth checking when validating certificate chains. A remote attacker can supply a certificate chain to cause incorrect enforcement of certificate-chain depth limits.