CVE-2026-8367
EUVD-2026-3004213.05.2026, 16:17
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| aria2_project | aria2 | 𝑥 < 1.37.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration