{"id":"OESA-2026-4134","summary":"jss security update","details":"Java Security Services (JSS) is a java native interface which provides a bridge for java-based applications to use native Network Security Services (NSS). This only works with gcj. Other JREs require that JCE providers be signed.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.(CVE-2026-78323)","modified":"2026-10-01T02:00:04.750687872Z","published":"2026-09-30T13:46:55Z","upstream":["CVE-2026-78323"],"database_specific":{"severity":"Medium"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4134"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78323"}],"affected":[{"package":{"name":"jss","ecosystem":"openEuler:24.03-LTS-SP4","purl":"pkg:rpm/openEuler/jss&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.2-3.oe2403sp4"}]}],"ecosystem_specific":{"aarch64":["jss-5.4.2-3.oe2403sp4.aarch64.rpm","jss-debuginfo-5.4.2-3.oe2403sp4.aarch64.rpm","jss-debugsource-5.4.2-3.oe2403sp4.aarch64.rpm","jss-help-5.4.2-3.oe2403sp4.aarch64.rpm"],"src":["jss-5.4.2-3.oe2403sp4.src.rpm"],"x86_64":["jss-5.4.2-3.oe2403sp4.x86_64.rpm","jss-debuginfo-5.4.2-3.oe2403sp4.x86_64.rpm","jss-debugsource-5.4.2-3.oe2403sp4.x86_64.rpm","jss-help-5.4.2-3.oe2403sp4.x86_64.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-4134.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}