CYBERSECURITY BRIEFING NOTE OVERVIEW CVE-2026-33753 is an authorization bypass vulnerability in rfc3161-client, a Python library implementing RFC 3161's Time-Stamp Protocol (TSP). The flaw allows attackers to impersonate trusted Time-Stamping Authorities (TSAs) by exploiting a logic error in certificate extraction from PKCS#7 structures. Attackers can inject a spoofed certificate with matching Common Name and Extended Key Usage attributes, causing the library to validate authorization against the forged certificate while performing cryptographic signature verification against a legitimate TSA, thereby completely bypassing TSA pinning controls. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no privilege or user interaction. Attack complexity is low, making exploitation straightforward. While there is no confidentiality impact, the integrity impact is high, as attackers can generate fraudulent time-stamp tokens that appear legitimate. The vulnerability affects rfc3161-client versions prior to 1.0.6. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and does not appear to be under active exploitation. The EPSS score of 0.000070000 indicates minimal observed exploitation activity. However, the relatively straightforward nature of the attack and the critical importance of time-stamping in digital signature validation suggest organizations should prioritize patching to version 1.0.6 regardless of current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.6CPE matchmatch criteria | cpe:2.3:a:trailofbits:rfc3161-client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.