Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33753

28
FAUCET Score

CYBERSECURITY BRIEFING NOTE OVERVIEW CVE-2026-33753 is an authorization bypass vulnerability in rfc3161-client, a Python library implementing RFC 3161's Time-Stamp Protocol (TSP). The flaw allows attackers to impersonate trusted Time-Stamping Authorities (TSAs) by exploiting a logic error in certificate extraction from PKCS#7 structures. Attackers can inject a spoofed certificate with matching Common Name and Extended Key Usage attributes, causing the library to validate authorization against the forged certificate while performing cryptographic signature verification against a legitimate TSA, thereby completely bypassing TSA pinning controls. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no privilege or user interaction. Attack complexity is low, making exploitation straightforward. While there is no confidentiality impact, the integrity impact is high, as attackers can generate fraudulent time-stamp tokens that appear legitimate. The vulnerability affects rfc3161-client versions prior to 1.0.6. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and does not appear to be under active exploitation. The EPSS score of 0.000070000 indicates minimal observed exploitation activity. However, the relatively straightforward nature of the attack and the critical importance of time-stamping in digital signature validation suggest organizations should prioritize patching to version 1.0.6 regardless of current threat activity.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.0.6CPE matchmatch criteria
cpe:2.3:a:trailofbits:rfc3161-client:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.2MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.5
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
8.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 1st percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: rfc3161-clientFixed in: 1.0.6
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-3xxc-pwj6-jgrjmedium

rfc3161-client Has Improper Certificate Validation

Apr 8, 2026

References

github.com / trailofbits/rfc3161-client/security/advisories/GHSA-3xxc-pwj6-jgrj
ExploitVendor Advisory