Executive brief
OCaml-TLS is a library used to secure network communications. A flaw in its server implementation allows an attacker to bypass security checks during client authentication by using a certificate that was never intended for that purpose (such as a standard website certificate). This could allow unauthorized users to impersonate legitimate clients and gain access to restricted services or sensitive data.
Technical details
The OCaml-TLS server implementation fails to validate the KeyUsage and ExtendedKeyUsage (EKU) extensions of client certificates during mutual TLS (mTLS) authentication. Specifically, the library does not verify that the 'digitalSignature' bit is set in KeyUsage or that 'clientAuth' is present in the EKU. This allows an attacker who possesses a valid certificate issued by a trusted Certificate Authority (CA)—even if that certificate was only intended for server authentication (serverAuth)—to successfully authenticate as a client. The vulnerability is most severe in environments where a broad trust store (like Mozilla's public PKI) is used for mTLS, or where internal CAs issue both server and client certificates. The issue is fixed in OCaml-TLS version 2.1.0.
Affected products
- OCaml-TLS tls < 2.1.0
Timeline
- 2026-04-24: disclosed: Vulnerability discovered
- 2026-05-09: other: Reported to OCaml security team
- 2026-05-20: patched: Version 2.1.0 released
- 2026-06-15: advisory: CVE-2026-45389 published