Threats Tagged 'cve-2026-33753'
View all threats tagged with 'cve-2026-33753'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-33753'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-33753 is an authorization bypass vulnerability in the rfc3161-client Python library prior to version 1.0.6. The flaw arises from improper certificate validation during signature verification, allowing an attacker to impersonate a trusted Time-Stamping Authority (TSA). This is achieved by exploiting a logic error in extracting the leaf certificate from an unordered PKCS#7 certificate bag, enabling the attacker to append a spoofed certificate that meets the required common_name and Extended Key Usage (EKU) criteria. The library then incorrectly validates authorization rules against the forged certificate while verifying the cryptographic signature against a legitimate TSA certificate, bypassing TSA authorization pinning. The vulnerability has a CVSS 3.1 score of 6.2 (medium severity) and is fixed in version 1.0. Join the discussion | CVE Database V5 | 04/08/2026, 14:54:59 UTC Added: 04/08/2026, 15:20:50 UTC |
Showing 1 to 1 of 1 result