The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope.
References
Configurations
No configuration.
History
11 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
11 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 16:16
Updated : 2026-06-11 17:16
NVD link : CVE-2026-9648
Mitre link : CVE-2026-9648
CVE.ORG link : CVE-2026-9648
JSON object : View
Products Affected
No product.
CWE
No CWE.
