TrustAsia Pulls 143 Certificates Following Critical LiteSSL ACME Vulnerability
TrustAsia has revoked 143 SSL/TLS certificates due to a critical vulnerability identified in its LiteSSL ACME service.
TrustAsia has revoked 143 SSL/TLS certificates due to a critical vulnerability identified in its LiteSSL ACME service.
The vulnerability, disclosed on Tue, Jan 21, 2026, allowed the reuse of domain validation data across different ACME accounts, facilitating unauthorized certificate issuance for domains validated by other users.
This issue contravened the CA/Browser Forum Baseline Requirements, which require unique domain validation for each certificate issuance.
The vulnerability originated from a logic error in LiteSSL's ACME service handling of Authorization objects, failing to verify whether a Certificate Signing Request (CSR) came from the same ACME account that performed the initial validation.
Attackers were able to exploit this to obtain wildcard certificates for arbitrary domains without re-triggering DNS-01 challenges. Additionally, an excessively prolonged cache for DNS-01 validation challenges was discovered, extending the exploitation window.
Field Value
Certificate Authority TrustAsia
Affected Service LiteSSL ACME
Vulnerability Type Domain Validation Reuse / Authorization Bypass
Certificates Impacted 143 total (140 revoked, 3 previously revoked)
Issuance Period After Dec 29, 2025
TrustAsia has revoked 143 SSL/TLS certificates due to a critical vulnerability identified in its LiteSSL ACME service.
Protocol ACME (DNS-01 challenge)
Following the confirmation of the vulnerability, TrustAsia suspended ACME issuance services and initiated system remediation. Code fixes were deployed, and 140 valid certificates were revoked, with three having been previously revoked.
All ACME Authorizations were reset from VALID to REVOKED status, requiring clients to perform re-validation before certificate issuance could resume.
TrustAsia will publish a Full Incident Report, detailing root cause analysis and the non-compliance start date.
Time (UTC+8) Event Details
14:55 Report Received Community report via V2EX flagged domain validation reuse issue
15:10 Preliminary Confirmation Issue confirmed; ACME issuance service suspended immediately
15:30 Scope Investigation Impact scope identified; certificate investigation began
15:33 Initial Revocation Two certificates from community report revoked
21:00 Code Fix Completed Fix validated successfully in test environment
21:21 Full Scope Identified All 143 affected certificates identified; batch revocation initiated
21:30 Revocation Completed 140 valid certificates revoked (3 previously revoked)
21:41 Production Deployment Patched code deployed to production environment
22:35 Authorization Reset All ACME Authorizations reset from VALID to REVOKED; re-validation requested
22:50 Internal Validation Production environment validation completed successfully
23:00 Service Restored External ACME issuance service fully restored
TrustAsia rapidly contained the vulnerability within 8 hours and fully remediated the service. Organizations that issued certificates via LiteSSL ACME between Dec 29, 2025, and Jan 21, 2026, should verify certificate status and prepare for potential re-issuance requirements.
This incident highlights the critical importance of proper account context validation in ACME implementations and the necessity of strict separation between user domains during certificate validation workflows.
Based on reporting by GBHackers.
