PT-2026-31068 · Openssl+2 · Openssl+2
1Seal
+2
·
Published
2026-04-07
·
Updated
2026-05-21
·
CVE-2026-33810
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
versions prior to 2.3
Description
When verifying a certificate chain with excluded DNS constraints, these constraints are not correctly applied to wildcard DNS Subject Alternative Names (SANs) that differ in case. This impacts the validation of trusted certificate chains issued by a root Certificate Authority (CA) in the system or specified root certificate pool.
Recommendations
Update to a version prior to 2.3.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl
Red Os
Rocky Linux