Overview
What is CVE-2026-42508?
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
Vulnerability intelligence
CVE-2026-42508 and is rated Critical severity with a CVSS score of 9.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.