← Internet Security Research Group cases
Bugzilla #1972745 Self Reported Incident

Let's Encrypt: Deployed Unreviewed Boulder Code

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is an incident report from Let’s Encrypt about a deployment of Boulder CA software that was tagged using an unreviewed commit. The incident was triggered when a core developer accidentally tagged a Boulder release (release-2025-06-09) with a commit that had not been reviewed and merged into the main branch, and that release was deployed. After detection, the Boulder team reviewed the commit and stated it only removed dead code and did not cause incorrect operation of the CA, and they did not stop issuance during the incident period. The report explains that the gap was between automated systems enforcing reviewed commits on main and the release process assumptions for signed release tags, including that release tag verification was not automated. Let’s Encrypt reported remediation by improving automation for release tagging and release artifact builds to verify that tagged commits are reviewed and integration tests pass, and by reviewing historical release tags to ensure no other unreviewed code had been deployed to production. The bug is resolved as FIXED, with a report closure summary stating that all disclosed action items were completed and requesting closure.

Model: gpt-5.4-nano Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.90 10 comments
Chronology
  1. A Boulder release tag was created and deployed based on an unreviewed commit.
  2. The incident was detected and Let’s Encrypt began incident response and remediation.
  3. Let’s Encrypt posted a report closure summary stating remediation and action items were completed.
Thread Activity
  1. Internet Security Research Group — Posted a full incident report describing the unreviewed commit tagged into a deployed Boulder release and the impact (0 certificates), plus the remediation and timeline.
  2. Community commenter — Asked why issuance was not stopped and why the event was not treated as a revocation scenario.
  3. Internet Security Research Group — Explained that the significance was determined quickly, that mandatory revocation circumstances did not apply, and described additional protections added for hotfix release branches and tag protection rules.
  4. Internet Security Research Group — Provided an update on action items, including completion of a GitHub Actions step verifying tag commit ancestry and progress on other items.
  5. Internet Security Research Group — Updated that automated release tagging support was merged and that remaining analysis and script checks were in progress.
  6. Internet Security Research Group — Reported completion of all action items, including analysis of historical release tags and confirmation that no other unreviewed code was deployed.
  7. Internet Security Research Group — Posted the report closure summary, stating remediation improvements and historical tag review were completed and requesting closure.
  8. CCADB representative — Issued a final call for comments and noted the bug would be closed on approximately 2025-07-29.
Participants
Internet Security Research Group Community commenter CCADB representative
Similar Local Cases
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 95% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 89% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 88% similar
Let's Encrypt: Early CRL Removal Incident
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 87% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#1955721 RESOLVED Self Reported Incident Vulnerability Disclosure Opened 2025-03-21 · Closed 2025-06-10 · 87% similar
Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities
#1577652 RESOLVED Self Reported Incident Revocation Issue Opened 2019-08-29 · Closed 2022-11-14 · 86% similar
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 86% similar
Let's Encrypt: CAA Rechecking bug

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action