logo

TrustAsia Pulls 143 Certificates Following Critical LiteSSL ACME Vulnerability

ID: 803401ba-5e32-567f-a9f5-10f45dec7bdd

STIX ID: report--803401ba-5e32-567f-a9f5-10f45dec7bdd

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-01-23

Date Updated: 2026-04-22

Author: Divya

...
...

TrustAsia discovered a critical logic flaw in its LiteSSL ACME implementation that allowed domain validation data to be reused across ACME accounts, enabling unauthorized issuance of certificates (including wildcard certs). The company suspended ACME issuance, applied code fixes, revoked 140 still-valid certificates (143 impacted in total), reset all ACME authorizations to REVOKED, and restored service within about eight hours; a full incident report and root-cause details are forthcoming.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.