← Internet Security Research Group cases
Bugzilla #1955721
Self Reported Incident
Vulnerability Disclosure
Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities
RESOLVED
FIXED
Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Let's Encrypt self-reported an incident involving the failure to document and remediate critical vulnerabilities identified during weekly scans. The incident was triggered by a lack of timely documentation and remediation of vulnerabilities with CVSSv2 scores of 7.0 or higher, as required by their Network and Certificate System Security Requirements. The CA took immediate action by triaging and addressing the vulnerabilities and updated their Vulnerability Response Procedure to prevent future occurrences. The incident was resolved with a new procedure and training completed by May 14, 2025.
Chronology
- Non-compliance with vulnerability documentation begins.
- Non-compliance identified by Let's Encrypt.
- Training on new vulnerability response procedure completed.
Thread Activity
- Internet Security Research Group — Let's Encrypt identified a failure to document a compensating control for a critical vulnerability.
- Internet Security Research Group — Full incident report submitted detailing multiple instances of non-compliance.
- Internet Security Research Group — New vulnerability response procedure published and weekly meetings initiated.
- Internet Security Research Group — Training on the new procedure completed, marking the remediation of the incident.
Participants
Community commenter
Google representative
CCADB representative
External References
Similar Local Cases
Let's Encrypt: Deployed Unreviewed Boulder Code
Let's Encrypt: Early CRL Removal Incident
Let's Encrypt: Failure to provide OCSP Responses for some certificates
Let's Encrypt: Incomplete and Inconsistent CRLs
Let's Encrypt: CAA Rechecking bug
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate