[Pkg-freeipa-devel] Bug#1145877: jss: CVE-2026-78323

Salvatore Bonaccorso carnil at debian.org
Thu Aug 27 13:56:41 BST 2026


Source: jss
Version: 5.9.0~beta3-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerability was published for jss.

CVE-2026-78323[0]:
| A flaw was found in JSS (Java Security Services). The
| JSSTrustManager class does not verify NSS trust flags when
| validating CA certificates, allowing certificates present in the NSS
| database without TRUSTED_CA flags to be accepted as trust anchors
| for TLS connections. In non-default configurations where certificate
| revocation checking is disabled, this could allow a man-in-the-
| middle attacker to forge certificates accepted by PKI client
| connections.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78323
    https://www.cve.org/CVERecord?id=CVE-2026-78323
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2521775

Please adjust the affected versions in the BTS as needed.

Actually at time of writing the only reference is the Red Hat bug, so
I'm uncertain about further references, can you explore/check with
upstream?

Regards,
Salvatore



More information about the Pkg-freeipa-devel mailing list