CVE-2026-9648: X.509 NameConstraints Bypass in crypton-x509-validation
ID: 54c2c5a4-1e54-5148-9f06-e4b815068042
STIX ID: report--54c2c5a4-1e54-5148-9f06-e4b815068042
Feed Name: CosmicBytez Labs
Threat Score
A critical vulnerability (CVE-2026-9648, CVSS 9.1) in the Haskell crypton-x509-validation library allows TLS clients to accept certificates whose Subject Alternative Names fall outside the permitted subtrees defined by a name-constrained intermediate CA, negating X.509 NameConstraints and enabling MitM/spoofing; immediate actions include updating the library, auditing dependencies, and reviewing PKI practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
