App store server library: Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
The Apple App Store Server Python Library's SignedDataVerifier component improperly validates OCSP responses by accepting stale 'GOOD' responses indefinitely. This flaw allows replay of expired OCSP responses, bypassing certificate revocation checks. Applications using this library with online checks enabled may continue to trust revoked certificates if a stale OCSP response is replayed. The vulnerability affects versions from 0.2.0 up to but not including 3.1.2. No patch information is currently provided.
AI Analysis
Technical Summary
The SignedDataVerifier in the Apple App Store Server Python Library attempts online certificate revocation checking via OCSP when enabled. However, its OCSP validation logic in _ChainVerifier.check_ocsp_status() verifies the OCSP response signature and CertID but does not validate the freshness timestamps (producedAt, thisUpdate, nextUpdate). Consequently, stale but previously valid OCSP 'GOOD' responses can be replayed indefinitely, causing the library to incorrectly accept revoked certificates as valid. This affects versions >=0.2.0 and <3.1.2 of the library.
Potential Impact
This vulnerability allows an attacker to bypass certificate revocation checks by replaying stale OCSP 'GOOD' responses. As a result, applications relying on this library with online revocation checking enabled may continue to accept JWS objects signed with revoked keys, potentially undermining trust in the certificate validation process. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling online OCSP checks or implementing additional certificate revocation validation mechanisms outside this library to mitigate risk.
App store server library: Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
Description
The Apple App Store Server Python Library's SignedDataVerifier component improperly validates OCSP responses by accepting stale 'GOOD' responses indefinitely. This flaw allows replay of expired OCSP responses, bypassing certificate revocation checks. Applications using this library with online checks enabled may continue to trust revoked certificates if a stale OCSP response is replayed. The vulnerability affects versions from 0.2.0 up to but not including 3.1.2. No patch information is currently provided.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The SignedDataVerifier in the Apple App Store Server Python Library attempts online certificate revocation checking via OCSP when enabled. However, its OCSP validation logic in _ChainVerifier.check_ocsp_status() verifies the OCSP response signature and CertID but does not validate the freshness timestamps (producedAt, thisUpdate, nextUpdate). Consequently, stale but previously valid OCSP 'GOOD' responses can be replayed indefinitely, causing the library to incorrectly accept revoked certificates as valid. This affects versions >=0.2.0 and <3.1.2 of the library.
Potential Impact
This vulnerability allows an attacker to bypass certificate revocation checks by replaying stale OCSP 'GOOD' responses. As a result, applications relying on this library with online revocation checking enabled may continue to accept JWS objects signed with revoked keys, potentially undermining trust in the certificate validation process. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling online OCSP checks or implementing additional certificate revocation validation mechanisms outside this library to mitigate risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8f6j-263m-g72x
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a55ff8968715ace432f46df
Added to database: 07/14/2026, 09:21:13 UTC
Last enriched: 07/14/2026, 09:45:25 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.