Trust Broken: Critical Keylime Flaw (CVSS 9.4) Disables mTLS Authentication
ID: 0656e89a-c207-57c4-8185-26455b35d2e1
STIX ID: report--0656e89a-c207-57c4-8185-26455b35d2e1
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-1709) was found in Keylime's registrar—introduced in versions 7.12.0 through 7.13.0—that effectively disables mutual TLS client certificate enforcement (ssl.CERT_OPTIONAL vs ssl.CERT_REQUIRED), allowing clients to connect to protected API endpoints without valid certificates; the flaw is rated CVSS 9.4 and maintainers advise upgrading to the patched version or applying mitigations such as firewall-based network isolation or an mTLS-enforcing reverse proxy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
