← Back to CVE List
CVE-2026-9648NVD
Vulnerability Summary
The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
External References
- https://github.com/haskell/security-advisories/pull/332
- https://github.com/kazu-yamamoto/crypton-certificate/pull/30
- https://github.com/kazu-yamamoto/crypton-certificate/pull/30/changes/f4b77edf6ead77f4a886da40e41eab20f0180e39
- https://hackage.haskell.org/package/crypton-x509-validation-1.9.1/revisions/
- https://www.kb.cert.org/vuls/id/862559