logo

Haskell TLS Vulnerability Lets Attackers Forge Trusted Certificates (CVE-2026-9648)

ID: cb38b872-f103-58d9-84b9-adf7f20e4a6c

STIX ID: report--cb38b872-f103-58d9-84b9-adf7f20e4a6c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Do Son

...
...

A critical Haskell TLS vulnerability (CVE-2026-9648) in the crypton-x509-validation libraries omits X.509 NameConstraints checks, allowing an attacker with control of a name‑constrained subordinate CA to issue certificates for unauthorized domains and perform TLS man‑in‑the‑middle attacks; the flaw carries a CVSS of 9.1, affects all prior versions, and is patched in crypton-x509-validation v1.9.1 — organizations (particularly those using delegated PKI such as banks and insurers) should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.