CyberSec.Space Logo
Back to CVE Browser

CVE-2026-9648

CRITICAL
9.1
CVSS Severity Score
EPSS Score0.1560%
EPSS Percentile3.80th
PublishedJun 11, 2026
Last ModifiedJun 11, 2026

Vulnerability Description

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CAโ€™s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities