PT-2026-28601 · Unknown+1 · Cryptography+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
cryptography versions prior to 46.0.6
Description
DNS name constraints were only validated against Subject Alternative Names (SANs) within child certificates, rather than the
peer name presented during each validation. This allows a peer, such as bar.example.com, to validate against a wildcard leaf certificate for *.example.com, even if the parent certificate or higher in the chain contains an excluded subtree constraint for bar.example.com. This issue stems from a gap between RFC 5280, which defines Name Constraint semantics, and RFC 9525, which defines service identity semantics, as neither explicitly states if Name Constraints should apply to peer names.Recommendations
Update to version 46.0.6 or newer.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Cryptography