VDB
GCVE-110-TWILIO-2026-0023
GCVE-110-TWILIO-2026-0023
Advisory Published
<p>On September 9, 2026, Twilio will rotate the end-user TLS certificate for all REST API endpoints. Only the end-user certificate and certificate serial number will be renewed; root and intermediate certificates will remain the same.</p>
<p>This is a routine update that won’t impact most customers unless they’re pinning certificates or are managing them manually. Customers using the <a href="https://www.twilio.com/docs/libraries/reference/">Twilio Helper Libraries</a> don’t need to take any action since the change will be handled automatically. </p>
<p>Twilio recommends against certificate pinning because it creates potential security risks, can cause downtimes for services, and a higher probability of failed API requests.</p>
<p><b>How to test your connection</b></p>
<p>The new certificate will be available for testing at https://tls-test.twilio.com starting August 12, 2026. If the request succeeds with a 200 OK, no further action is required.</p>
<p><b>Need a hand?</b></p>
<p>These resources have more detail:</p>
<ul>
<li><p><a href="https://help.twilio.com/articles/226478767-Monitoring-Updates-to-Twilio-REST-API-Security-Settings">Monitoring Updates to Twilio REST API Security Settings</a></p>
</li>
<li><p><a href="https://www.twilio.com/docs/usage/security">Security best practices</a></p>
</li>
</ul>
Browse GCVE Records
800 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.