PT-2026-46040 · Unknown+1 · X509-Validation+3
CVE-2026-9648
·
Published
2026-06-03
·
Updated
2026-06-22
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
crypton-x509-validation versions prior to 1.9.1
crypton-x509 versions prior to 1.9.1
x509 (affected versions not specified)
x509-validation (affected versions not specified)
Description
The crypton-x509-validation and crypton-x509 libraries fail to enforce the X.509 Name Constraints extension during certificate validation. The Name Constraints extension is a mechanism that restricts the namespace, including permitted and excluded subtrees, for which a Certificate Authority (CA) is authorized to issue certificates. This failure allows TLS clients to accept certificates with Subject Alternative Names (SANs) that fall outside the issuing CA's permitted subtrees. Consequently, an attacker who compromises a name-constrained sub-CA's private key can issue certificates for domains beyond the intended scope, enabling the impersonation of arbitrary domains and man-in-the-middle attacks on TLS connections.
Recommendations
Update crypton-x509-validation to version 1.9.1.
Update crypton-x509 to version 1.9.1.
At the moment, there is no information about a newer version that contains a fix for this vulnerability regarding x509 and x509-validation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crypto/X509
Crypton-X509-Validation
X509
X509-Validation