X.509 NameConstraints Bypass in Haskell Library - crypton-x509-validation
CVE-2026-9648
9.1CRITICAL
What is CVE-2026-9648?
The crypton-x509-validation Haskell library has a flaw that allows TLS clients to accept certificates with Subject Alternative Names that do not conform to the constraints set by the issuing Certificate Authority (CA). This vulnerability occurs due to a failure to properly enforce X.509 NameConstraints, which can lead to domain impersonation if an attacker compromises a name-constrained sub-CA. As a result, attackers can potentially issue valid certificates for domains beyond the assigned constraints, posing significant risks to secure communications.
Affected Version(s)
crypton-certificate 0 < 1.9.1
