PT-2026-28601 · Unknown+1 · Cryptography+1

·

CVE-2026-34073

·

Published

2026-03-27

·

Updated

2026-08-24

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions cryptography versions prior to 46.0.6
Description DNS name constraints were only validated against Subject Alternative Names (SANs) within child certificates, rather than the peer name presented during each validation. This allows a peer, such as bar.example.com, to validate against a wildcard leaf certificate for *.example.com, even if the parent certificate or higher in the chain contains an excluded subtree constraint for bar.example.com. This issue stems from a gap between RFC 5280, which defines Name Constraint semantics, and RFC 9525, which defines service identity semantics, as neither explicitly states if Name Constraints should apply to peer names.
Recommendations Update to version 46.0.6 or newer.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14094
CLEANSTART-2026-AN24336
CLEANSTART-2026-AN27706
CLEANSTART-2026-AZ09261
CLEANSTART-2026-FU07345
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-34073
ECHO-4B9F-FBF8-C429
GHSA-M959-CC7F-WV43
OPENSUSE-SU-2026:10454-1
OPENSUSE-SU-2026:20506-1
PYSEC-2026-35
RHSA-2026:7295
SUSE-SU-2026:21021-1
SUSE-SU-2026:21116-1
SUSE-SU-2026:21126-1
SUSE-SU-2026:21165-1

Affected Products

Red Os
Cryptography