Hi, On Thu, Aug 27, 2026 at 02:56:41PM +0200, Salvatore Bonaccorso wrote: > Source: jss > Version: 5.9.0~beta3-4 > Severity: important > Tags: security upstream > X-Debbugs-Cc: [email protected], Debian Security Team > <[email protected]> > > Hi, > > The following vulnerability was published for jss. > > CVE-2026-78323[0]: > | A flaw was found in JSS (Java Security Services). The > | JSSTrustManager class does not verify NSS trust flags when > | validating CA certificates, allowing certificates present in the NSS > | database without TRUSTED_CA flags to be accepted as trust anchors > | for TLS connections. In non-default configurations where certificate > | revocation checking is disabled, this could allow a man-in-the- > | middle attacker to forge certificates accepted by PKI client > | connections. > > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > For further information see: > > [0] https://security-tracker.debian.org/tracker/CVE-2026-78323 > https://www.cve.org/CVERecord?id=CVE-2026-78323 > [1] https://bugzilla.redhat.com/show_bug.cgi?id=2521775 > > Please adjust the affected versions in the BTS as needed. > > Actually at time of writing the only reference is the Red Hat bug, so > I'm uncertain about further references, can you explore/check with > upstream?
Upstream repository contains the following commit referencing the CVE: https://github.com/dogtagpki/jss/commit/cffadbb2b53157014bc2ffb46d5a8fd4979623d1 Regards, Salvatore

