Cyber Security News

TrustAsia Revoked 143 Certificates Following LiteSSL ACME Service Vulnerability

TrustAsia has revoked 143 SSL/TLS certificates following the discovery of a vulnerability in its LiteSSL ACME service. The flaw allowed for the improper reuse of domain validation data across different ACME accounts, prompting an immediate suspension of issuance services and a subsequent mass revocation of affected certificates.

The incident, tracked under Mozilla Bugzilla ticket #2011713, was triggered by a community report received on January 21, 2026. The vulnerability specifically impacted certificates issued via the ACME protocol after December 29, 2025.

Technical Root Cause and Impact

The core issue stemmed from a logic error in the LiteSSL ACME service handling of Authorization objects. Investigations revealed that “Authorization data was reused across different ACME accounts,” effectively bypassing the requirement for unique validation per account context.

While community speculation initially suggested the issue might be related to External Account Binding (EAB) assignments in the database, TrustAsia clarified that their architecture maintains a strict one-to-one mapping between ACME Accounts and EABs.

Incident Scope:

  • Total Certificates Impacted: 143
  • Affected Protocol: ACME (Automated Certificate Management Environment)
  • Vulnerable Period: Issuance dates post-2025-12-29
  • Status: All affected certificates have been revoked; the service is patched and online.

The following timeline outlines the response actions taken by TrustAsia on January 21, 2026 (Times in UTC+8).

TimeEvent Description
14:55Compliance team received a report (via V2EX) regarding domain validation reuse.
15:10Preliminary confirmation of the issue; ACME issuance service suspended.
15:30Impact scope confirmed; investigation into specific certificates began.
15:33Revocation initiated for the two specific certificates mentioned in the initial report.
21:00Code fix completed and validated in the test environment.
21:21Identification of all 143 affected certificates completed; batch revocation initiated.
21:30Revocation completed for the 140 remaining valid certificates (3 were previously revoked).
21:41Patched code deployed to the production environment.
22:35Reset of all ACME Authorizations from VALID to REVOKED, forcing client re-validation.
23:00External ACME issuance service fully restored.

This incident violates the CA/Browser Forum Baseline Requirements (TLS BR Version 2.2.2), specifically Section 3.2.2.4, which mandates that the Certificate Authority must validate each Fully-Qualified Domain Name (FQDN) prior to issuance.

TrustAsia has stated that a Full Incident Report will be released to the Mozilla Bugzilla thread, which will include a more detailed root cause analysis and the definitive start date of the non-compliance.

All ACME Authorizations in the production environment were reset to REVOKED status to prevent any lingering invalid authorizations from being used for new issuance.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

5 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

9 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

15 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

20 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

31 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago