CVE-2026-8367: aria2c Improper Certificate Validation

Published May 13, 2026
·
Updated

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

Affected Software

2 affected components
aria2 aria2c
Aria2 Project Aria2<1.37.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure aria2c validates the Extended Key Usage (EKU) field of TLS server certificates and only accepts certificates that include the TLS Web Server Authentication (serverAuth) purpose. If a configuration option is not available, apply vendor patches or rebuild with EKU checking enabled when a fix is provided.

    aria2c Extended Key Usage (EKU) validation = enforce serverAuth EKU
  2. Compensating control

    Until EKU validation is enforced in aria2c, restrict aria2c's network access to only trusted servers (via firewall rules, ACLs, or network segmentation) and use certificate pinning or manual verification of server certificate fingerprints to mitigate the risk of a reused/compromised certificate being accepted.

Event History

May 13, 2026
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-8367?

CVE-2026-8367 has been classified as a high severity vulnerability due to improper certificate validation.

2

How do I fix CVE-2026-8367?

To fix CVE-2026-8367, ensure you are using the latest version of aria2c that addresses this improper certificate validation issue.

3

What causes CVE-2026-8367?

CVE-2026-8367 is caused by aria2c accepting server certificates with incorrect Extended Key Usage (EKU), leading to potential misuse.

4

Who is affected by CVE-2026-8367?

Users of aria2 and aria2c versions prior to the fix are affected by CVE-2026-8367.

5

What are the potential risks of CVE-2026-8367?

The risks of CVE-2026-8367 include the possibility of attackers exploiting compromised certificates for TLS server authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203