logo

Trust Broken: Critical Keylime Flaw (CVSS 9.4) Disables mTLS Authentication

ID: 0656e89a-c207-57c4-8185-26455b35d2e1

STIX ID: report--0656e89a-c207-57c4-8185-26455b35d2e1

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-1709) was found in Keylime's registrar—introduced in versions 7.12.0 through 7.13.0—that effectively disables mutual TLS client certificate enforcement (ssl.CERT_OPTIONAL vs ssl.CERT_REQUIRED), allowing clients to connect to protected API endpoints without valid certificates; the flaw is rated CVSS 9.4 and maintainers advise upgrading to the patched version or applying mitigations such as firewall-based network isolation or an mTLS-enforcing reverse proxy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.