#1145877 jss: CVE-2026-78323

#1145877#5
Date:
2026-08-27 12:56:41 UTC
From:
To:
Hi,

The following vulnerability was published for jss.

CVE-2026-78323[0]:
| A flaw was found in JSS (Java Security Services). The
| JSSTrustManager class does not verify NSS trust flags when
| validating CA certificates, allowing certificates present in the NSS
| database without TRUSTED_CA flags to be accepted as trust anchors
| for TLS connections. In non-default configurations where certificate
| revocation checking is disabled, this could allow a man-in-the-
| middle attacker to forge certificates accepted by PKI client
| connections.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78323
https://www.cve.org/CVERecord?id=CVE-2026-78323
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2521775

Please adjust the affected versions in the BTS as needed.

Actually at time of writing the only reference is the Red Hat bug, so
I'm uncertain about further references, can you explore/check with
upstream?

Regards,
Salvatore