PT-2026-42353 · Cleanstart · Openbao-Fips

Published

2026-04-30

·

Updated

2026-04-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Multiple security vulnerabilities affect the openbao-fips package. During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions. See references for individual vulnerability details.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CLEANSTART-2026-WB89098

Affected Products

Openbao-Fips