CVE-2026-33753Disclosure(trailofbits / rfc3161-client)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic flaw in how the library extracts the leaf certificate from an unordered PKCS#7 bag of certificates, an attacker can append a spoofed certificate matching the target common_name and Extended Key Usage (EKU) requirements. This tricks the library into verifying these authorization rules against the forged certificate while validating the cryptographic signature against an actual trusted TSA (such as FreeTSA), thereby bypassing the intended TSA authorization pinning entirely. This vulnerability is fixed in 1.0.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rfc3161-client

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
rfc3161-client

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-08: 3Technical Details · 2026-04-08: 204-08
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33753 rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-… https://www.cve.org/CVERecord?id=CVE-2026-33753 ----- Traducción: CVE-2026-33753 rfc… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-33753 as an Authorization Bypass in rfc3161-client before version 1.0.6, with no proof of concept, exploit code, active exploitation, or patch information provided.

    0000029
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33753 rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-… https://www.cve.org/CVERecord?id=CVE-2026-33753

    Post summary

    A new CVE (CVE-2026-33753) affecting the rfc3161‑client library is disclosed, describing an authorization bypass flaw present before version 1.0.6.

    00000121
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33753 Authorization Bypass in rfc3161-client Signature Verification Pri... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33753 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references CVE-2026-33753 with a brief title and links to details and alerts but provides no substantive information about the vulnerability.

    0000039
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptrailofbitsrfc3161-client---

Explore more