PT-2026-67529 · Pypi · Cryptography

CVE-2026-69248

·

Published

2026-08-03

·

Updated

2026-09-08

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions cryptography versions prior to 49.0.0
Description A flaw exists in the verifier where a wildcard pattern in the DNS Subject Alternative Name (SAN) of a leaf certificate is incorrectly treated as matching a more-specific permitted constraint of an intermediate constrained Certificate Authority (CA). Specifically, the DNSConstraint::matches function allows a wildcard such as *.example.com to expand to sibling names like bar.example.com, even if the CA is restricted to foo.example.com. This behavior enables the acceptance of an invalid certificate chain, allowing a scope escape outside of the permitted names.
Recommendations Update to version 49.0.0.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:64774
ALSA-2026:64795
CVE-2026-69248
ECHO-1E23-77EB-13C2
GHSA-M2H6-J472-RP4C
OPENSUSE-SU-2026:21685-1
PYSEC-2026-3554
SUSE-SU-2026:23196-1
SUSE-SU-2026:23247-1
SUSE-SU-2026:23404-1

Affected Products

Cryptography