PT-2026-98288 · Php · Php

·

CVE-2026-91769

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP (affected versions not specified)
Description OpenSSL stream peer verification incorrectly handles certificate validation by falling back to the Common Name (CN) when no entries in the subjectAltName (SAN) match. According to RFC 6125, the CN should be ignored if the certificate contains any service identity. This behavior allows a certificate trusted for one name to be used to impersonate another if the CN matches the requested peer name despite a non-matching DNS SAN.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91769
OPENSUSE-SU-2026:11901-1

Affected Products

Php