logo

Wildcard Hijack: TrustAsia Revokes 143 Certificates After LiteSSL Vulnerability

ID: 73c73225-94e4-5440-b568-045acadc4720

STIX ID: report--73c73225-94e4-5440-b568-045acadc4720

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-23

Date Updated: 2026-04-23

Author: Ddos

...
...

LiteSSL (operated by TrustAsia) had a critical ACME implementation flaw: the service misattributed client IPs to an internal reverse proxy and failed to enforce that a certificate signing request originated from the same ACME account that performed DNS-01 validation. This allowed researchers to re-issue wildcard certificates for domains validated by others, creating a real risk of Man-in-the-Middle attacks; TrustAsia revoked 143 affected certificates, patched the service, reset ACME authorizations, and restored issuance on 2026-01-21. Users with LiteSSL certificates issued after 2025-12-29 are advised to check certificate status.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.