Incorrect authorization in LibreSSL - #VU153355
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass OCSP responder authorization.
The vulnerability exists due to improper authorization in the OCSP responder authorization checks in libtls and ocspcheck(8) when validating OCSP responder authorization. A remote attacker can provide an OCSP response to bypass OCSP responder authorization.