← GoDaddy cases
Bugzilla #1484766 Self Reported Incident Revocation Issue Security Incident

GoDaddy: Random Value Vulnerability in Domain Validation Method

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy disclosed a self-identified vulnerability in its domain validation code that could allow validation controls to be bypassed. The issue involved a “Random Value” generated for Method 3.2.2.4.6 and 3.2.2.4.7 being validated using Method 3.2.2.4.2 by persons who were not confirmed as the domain contact. GoDaddy stated the bug was introduced in November 2014 and was leveraged to issue a total of 865 certificates. GoDaddy reported that it closed the defect hours after identification and began scope and revocation activities in parallel. It stated that, in accordance with CA/B Forum BR section 4.9.1.1, all mis-issued certificates were revoked within 24 hours of identification, with revocation actions and follow-on identification described across 8/13–8/16. GoDaddy also said it updated its incident management process to include the discovered use case for any potential future incident. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:53 UTC Revised: 2026-06-16 18:37 UTC Confidence: 0.90 5 comments
Chronology
  1. GoDaddy stated the vulnerability was introduced in its validation code.
  2. GoDaddy identified the vulnerability as a possible revocation event and began scoping and revocation.
  3. GoDaddy reported that all certificates were revoked, with further research identifying additional affected certificates.
  4. GoDaddy reported additional certificates were identified and customers were notified of pending revocation.
  5. GoDaddy reported all certificates were revoked after additional identification.
  6. GoDaddy posted the incident report request and disclosed the incident details in this Bugzilla case.
Thread Activity
  1. Fastly representative — Wayne Thayer posted a request for an incident report and included GoDaddy’s disclosure that self-audits found a validation-bypass vulnerability affecting 865 certificates and that mis-issued certificates were revoked within 24 hours.
  2. GoDaddy — Daymion Reynolds provided a structured incident-report response including the revocation timeline, stated the bug was closed hours after identification, and described the defect as introduced in November 2014 due to an oversight.
  3. Community commenter — Ryan Sleevi asked for more details about how the defect scenario would work and requested clarification on incident management and the “further research” gap.
  4. Community commenter — Ryan Sleevi asked whether there were any updates.
  5. GoDaddy — Daymion Reynolds replied that the scenario described would not have been possible for an attacker, explained how Random Values were generated and distributed, and said GoDaddy updated its incident management process to include the use case.
Participants
Fastly representative GoDaddy Community commenter
Similar Local Cases
#1462844 RESOLVED Self Reported Incident Revocation Issue Opened 2018-05-19 · Closed 2023-02-22 · 100% similar
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1577913 RESOLVED Self Reported Incident Opened 2019-08-30 · Closed 2023-02-22 · 96% similar
GoDaddy: Issues with State and Country fields
#1605804 RESOLVED Self Reported Incident Opened 2019-12-24 · Closed 2023-02-22 · 89% similar
GoDaddy: Domain Validation Reuse Issue
#1572234 RESOLVED Self Reported Incident Repository Issue Opened 2019-08-07 · Closed 2023-02-22 · 88% similar
GoDaddy: cross certificate disclosure to CCADB
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 86% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1557085 RESOLVED Certificate Misissuance Revocation Issue Self Reported Incident Opened 2019-06-05 · Closed 2023-02-22 · 86% similar
Camerfirma: Intesa Sanpaolo misissued certificates
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 85% similar
DigiCert: Inconsistent EV audits
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 84% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action