PT-2026-46040 · Unknown+1 · X509-Validation+3

CVE-2026-9648

·

Published

2026-06-03

·

Updated

2026-06-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions crypton-x509-validation versions prior to 1.9.1 crypton-x509 versions prior to 1.9.1 x509 (affected versions not specified) x509-validation (affected versions not specified)
Description The crypton-x509-validation and crypton-x509 libraries fail to enforce the X.509 Name Constraints extension during certificate validation. The Name Constraints extension is a mechanism that restricts the namespace, including permitted and excluded subtrees, for which a Certificate Authority (CA) is authorized to issue certificates. This failure allows TLS clients to accept certificates with Subject Alternative Names (SANs) that fall outside the issuing CA's permitted subtrees. Consequently, an attacker who compromises a name-constrained sub-CA's private key can issue certificates for domains beyond the intended scope, enabling the impersonation of arbitrary domains and man-in-the-middle attacks on TLS connections.
Recommendations Update crypton-x509-validation to version 1.9.1. Update crypton-x509 to version 1.9.1. At the moment, there is no information about a newer version that contains a fix for this vulnerability regarding x509 and x509-validation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-9648
HSEC-2026-0008
OPENSUSE-SU-2026:11077-1
OPENSUSE-SU-2026:11078-1
OPENSUSE-SU-2026:11079-1
OPENSUSE-SU-2026:11080-1
OPENSUSE-SU-2026:11081-1
OPENSUSE-SU-2026:11082-1
OPENSUSE-SU-2026:11083-1
OPENSUSE-SU-2026:11084-1
OPENSUSE-SU-2026:11085-1
OPENSUSE-SU-2026:11087-1

Affected Products

Crypto/X509
Crypton-X509-Validation
X509
X509-Validation