When AIA is enabled, a client can send its leaf cert without the full chain of intermediate certificates requiring the AIA information to be used. There is no current way to verify the provided URI points to a legitimate source.
This issue has been addressed in the following products: OPENJDK ELS 11.0.30 Via RHSA-2026:0849 https://access.redhat.com/errata/RHSA-2026:0849
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:0931 https://access.redhat.com/errata/RHSA-2026:0931