See our SECURITY.txt for our policy on vulnerability disclosures.
Repository navigation
Security: trailofbits/rfc3161-client
Security
SECURITY.md
-
Verifier` trusts certificates embedded in the timestamp token, so a token under an unrelated self-signed root verifies against any configured rootGHSA-87gx-4x38-2j9q published
Sep 24, 2026 by DarkaMaulHigh -
Improper Certificate Validation in rfc3161-clientGHSA-3xxc-pwj6-jgrj published
Apr 8, 2026 by DarkaMaulModerate -
Insufficient verification of timestamp response signaturesGHSA-6qhv-4h7r-2g9m published
Jun 20, 2025 by woodruffwCritical
Learn more about advisories related to trailofbits/rfc3161-client in the GitHub Advisory Database