← GoDaddy cases
Bugzilla #1484766 Certificate Misissuance

GoDaddy: Random Value Vulnerability in Domain Validation Method

RESOLVED FIXED GoDaddy
AI Summary

GoDaddy identified a vulnerability in their domain validation method that allowed for the issuance of certificates without proper verification. This issue, introduced in November 2014, affected 865 certificates. Upon discovery, GoDaddy promptly revoked all affected certificates within 24 hours and has since improved their incident management processes to prevent similar occurrences in the future. The vulnerability was due to an oversight in token verification, which has since been addressed.

Model: gpt-4o-mini Generated: 2026-06-13 17:53 UTC Confidence: 0.90
Chronology
  1. Exploit issue surfaced as possible revocation event.
  2. All identified certificates revoked.
  3. Further certificates identified and revoked.
Participants
Wayne Thayer Daymion Reynolds
Similar Local Cases
#1462844 RESOLVED Certificate Misissuance Opened 2018-05-19 · Closed 2023-02-22 · 67% similar
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1520299 RESOLVED Certificate Misissuance Opened 2019-01-15 · Closed 2023-02-22 · 53% similar
Hongkong Post / Certizen: Failure to report misissuance
#1595921 RESOLVED Certificate Misissuance Opened 2019-11-12 · Closed 2023-02-22 · 53% similar
DigiCert: Domain validation skipped
#1777128 RESOLVED Certificate Misissuance Opened 2022-06-28 · Closed 2023-02-22 · 52% similar
GoDaddy: Misissuance of Cross Signed Certs
#1435770 RESOLVED Certificate Misissuance Opened 2018-02-05 · Closed 2023-02-22 · 52% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
#1909948 RESOLVED Certificate Misissuance Opened 2024-07-25 · Closed 2024-10-31 · 51% similar
GoDaddy: Edge Case for Data Reuse Outside of Timeframes
#1731939 RESOLVED Certificate Misissuance Opened 2021-09-22 · Closed 2023-02-22 · 51% similar
GoDaddy: Issued EV Wildcard Certificate
#1497703 RESOLVED Certificate Misissuance Opened 2018-10-09 · Closed 2023-02-22 · 51% similar
SECOM: Undisclosed intermediate certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action