Executive brief
JSS (Java Security Services) is a cryptography library that handles certificate validation for secure connections. A flaw in the JSSTrustManager class allows improperly configured systems to accept untrusted CA certificates, potentially enabling attackers to intercept and forge secure communications. This risk is limited to non-default configurations where certificate revocation checking has been disabled.
Technical details
The vulnerability is an improper certificate validation flaw (CWE-295) in the JSSTrustManager class, which fails to verify NSS trust flags when validating CA certificates. An attacker can exploit this via network-based man-in-the-middle attacks to present forged certificates that will be accepted as trust anchors for TLS connections, but only when certificate revocation verification is explicitly disabled (isCertRevocationVerify set to false)—a non-standard configuration. Default configurations are protected by native revocation verification (certChainRevokeVerify). The server-side TLS path using TomcatJSS (JSSNativeTrustManager) is not affected. Patches are expected to address this issue in affected Red Hat products.
Affected products
- Red Hat JSS <UNKNOWN>
Timeline
- 2026-08-24: disclosed