CVE-2023-32803: Amazon Ca-Certificates

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.

Affected products

  • Amazon Ca-Certificates: before 2021.2.50-72 (fixed in 2021.2.50-72)

Published 2026-09-14. Last modified 2026-09-22.