X.509: bypass of name constraints on wildcard SANs with matching peer names
Fixed in: >= 46.0.6
details
- Finding IDs
- F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001
- CVE
- CVE-2026-34073
- GHSA
- GHSA-m959-cc7f-wv43
- Status
- patched
- Fixed in
- >= 46.0.6
- Recorded credit
- Reporter: 1seal
- Note
- inferred mapping
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- X.509: bypass of name constraints on wildcard SANs with matching peer names
- Upstream CWE
- CWE-295
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001: Verification failures. Wildcard DNS names bypass certificate name constraints. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001
Security area (1seal assessment): Identity. Wildcard DNS names bypass certificate name constraints. Reviewed 24 Sep 2026.