CVE-2026-45388
critical · 9.1In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).
9.1
CVSS
0.2%
EPSS (exploit prob.)
13th
EPSS percentile
2026-06-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-295
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-45388