AWS-LC Cryptographic Library: Critical CRL Verification Bypass (CVE-2026-4428)
AWS-LC versions 1.24.0–1.71.0 have a logic error in CRL Distribution Point matching that lets revoked certificates slip through validation checks. If your app uses partitioned CRLs with IDP extensions and has CRL checking enabled, you need to update immediately. Good news: complete CRLs or disabled CRL checking aren't affected. Patch to AWS-LC 1.71.0+, AWS-LC-FIPS 3.3.0+, aws-lc-sys 0.39.0+, or aws-lc-fips-sys 0.13.13+ ASAP.
source: [aws/security-bulletin]