← Start Commercial (StartCom) Ltd. cases
Bugzilla #1283498 Security Incident Self Reported Incident

StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates

RESOLVED FIXED Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports that StartCom’s StartEncrypt project could be used, for about two weeks, to fraudulently obtain certificates for domains not under the user’s control, including domains such as google.com and dropbox.com. The issue was raised in the bug based on an external report (Computest) describing the vulnerability and its impact. StartCom stated that after Computest reported the problem, they fixed the bug and closed the StartEncrypt service/API the same day, and they announced this on their website. StartCom also stated that no certificates were effectively issued wrongfully due to backend checks, and that all issued certificates were correctly validated, so no certificates needed to be added to OneCRL. For future versions, StartCom decided to use the ACME protocol, and the old version was closed as of July 4. The bug is marked RESOLVED with resolution FIXED, and a later Mozilla comment notes that Mozilla took action against StartCom that included consideration of this issue.

Model: gpt-5.4-nano Generated: 2026-06-13 14:04 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.50 6 comments
Chronology
  1. Bug opened describing a StartEncrypt vulnerability that could enable fraudulent certificate issuance for domains not under the user’s control.
  2. StartCom fixed the reported bug and closed the StartEncrypt service/API; StartEncrypt old version closed as of this date.
  3. StartCom reported remediation details, including that no certificates required OneCRL updates and that future service would use ACME.
  4. Mozilla comment indicated Mozilla took action against StartCom, including consideration of this issue.
Thread Activity
  1. Community commenter — Reported that StartCom’s StartEncrypt could be used to fraudulently obtain certificates for domains not under the user’s control for about two weeks, citing an external blog post.
  2. Narzt representative — Expressed surprise that StartCom certificates were still being accepted and questioned whether this should lead to removal.
  3. Ipv representative — Pointed to an ongoing discussion in mozilla.dev.security.policy about the issue.
  4. Community commenter — Asked StartCom to confirm its stance and to answer questions about further actions, whether any certificates should be added to OneCRL, and the timeline for full resolution.
  5. Community commenter — Stated that the bug was fixed after Computest reported it, the API and StartEncrypt service were closed the same day, no certificates required OneCRL updates, and the old version was closed while future versions would use ACME.
  6. Community commenter — Noted that Mozilla took action against StartCom, including consideration of this issue.
Participants
Community commenter Narzt representative Ipv representative
Similar Local Cases
#499178 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2009-06-18 · Closed 2022-11-14 · 76% similar
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
#1024143 RESOLVED Self Reported Incident Opened 2014-06-11 · Closed 2022-11-14 · 76% similar
Disclosure of StartCom CA Certificates
#1405817 RESOLVED Certificate Misissuance Self Reported Incident Opened 2017-10-04 · Closed 2023-02-22 · 75% similar
Actalis: Certs issued with same issuer and serial number
#1689589 RESOLVED Self Reported Incident Security Incident Opened 2021-01-29 · Closed 2023-02-22 · 71% similar
Telia: Disallowed curve (P-521) in leaf certificate
#1386891 RESOLVED Self Reported Incident Opened 2017-08-02 · Closed 2023-02-22 · 70% similar
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
#1484766 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2018-08-20 · Closed 2024-06-30 · 70% similar
GoDaddy: Random Value Vulnerability in Domain Validation Method
#2012157 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2026-01-23 · Closed 2026-03-08 · 70% similar
Actalis: Issuance of certificate using keys previously reported as compromised
#1965828 RESOLVED Self Reported Incident Security Incident Opened 2025-05-12 · Closed 2025-08-19 · 69% similar
SwissSign: OCSP outage

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action