← Internet Security Research Group cases
Bugzilla #1955721 Self Reported Incident Vulnerability Disclosure

Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let's Encrypt self-reported an incident involving the failure to document and remediate critical vulnerabilities identified during weekly scans. The incident was triggered by a lack of timely documentation and remediation of vulnerabilities with CVSSv2 scores of 7.0 or higher, as required by their Network and Certificate System Security Requirements. The CA took immediate action by triaging and addressing the vulnerabilities and updated their Vulnerability Response Procedure to prevent future occurrences. The incident was resolved with a new procedure and training completed by May 14, 2025.

Model: gpt-4o-mini Generated: 2026-06-13 21:19 UTC Revised: 2026-06-16 19:24 UTC Confidence: 0.90 11 comments
Chronology
  1. Non-compliance with vulnerability documentation begins.
  2. Non-compliance identified by Let's Encrypt.
  3. Training on new vulnerability response procedure completed.
Thread Activity
  1. Internet Security Research Group — Let's Encrypt identified a failure to document a compensating control for a critical vulnerability.
  2. Internet Security Research Group — Full incident report submitted detailing multiple instances of non-compliance.
  3. Internet Security Research Group — New vulnerability response procedure published and weekly meetings initiated.
  4. Internet Security Research Group — Training on the new procedure completed, marking the remediation of the incident.
Participants
Community commenter Google representative CCADB representative
External References
Similar Local Cases
#1972745 RESOLVED Self Reported Incident Opened 2025-06-18 · Closed 2025-07-30 · 87% similar
Let's Encrypt: Deployed Unreviewed Boulder Code
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 86% similar
Let's Encrypt: Early CRL Removal Incident
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 80% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 79% similar
Let's Encrypt: CAA Rechecking bug
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 79% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1645276 RESOLVED Self Reported Incident Opened 2020-06-12 · Closed 2023-02-22 · 79% similar
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 78% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action