Skip to content

SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

Moderate
madrob published GHSA-8f6j-263m-g72x Jun 3, 2026

Package

pip app-store-server-library (pip)

Affected versions

>= 0.2.0, <= 3.1.1

Patched versions

3.1.2

Description

Summary

SignedDataVerifier attempts to perform online revocation checking when enable_online_checks=True, but its OCSP validation logic accepts stale GOOD responses as valid indefinitely. In appstoreserverlibrary/signed_data_verifier.py, _ChainVerifier.check_ocsp_status() verifies the OCSP response signature and CertID match, but never validates the freshness window carried by producedAt, thisUpdate, or nextUpdate.

As a result, a previously valid signed OCSP GOOD response can be replayed after it is expired, and the library will still treat the certificate as good. If an App Store signing certificate or intermediate is ever revoked, applications using this library with online checks enabled can continue accepting JWS objects signed with the revoked key as long as a stale signed OCSP response is replayed.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate. Learn more on MITRE.

Improper Check for Certificate Revocation

The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised. Learn more on MITRE.

Credits