CVE-2026-42790 Details
Description
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. permitted;DNS:allowed.example.com) to issue a leaf certificate that an OTP TLS client accepts as a valid identity for an out-of-scope hostname (e.g. victim.example.com): First, pubkey_cert:validate_names/6 in lib/public_key/src/pubkey_cert.erl only checks SAN DNS entries against nameConstraints. Per RFC 5280, a permitted DNS subtree only restricts certificates that contain a DNS-typed name. A leaf with no subjectAltName therefore trivially satisfies any permitted;DNS:... constraint regardless of its subject commonName. Second, public_key:pkix_verify_hostname/3 in lib/public_key/src/public_key.erl falls back to the subject commonName when no subjectAltName is present, extracting id-at-commonName attributes as presented IDs and matching them against the reference hostname. The strict pkix_verify_hostname_match_fun(https) matcher does not suppress this fallback. The result is that path validation accepts a CN-only leaf under a DNS-constrained intermediate (no SAN means the nameConstraints are not triggered), and hostname verification then accepts it via the CN fallback. The bypass is reachable from stock ssl:connect with verify_peer, a trusted CA, SNI, and the canonical strict https hostname matcher. This issue affects OTP from OTP 19.3 before OTP 29.0.1, OTP 28.5.0.1, OTP 27.3.4.12 and OTP 26.2.5.21, corresponding to public_key from 1.4 before 1.21.1, 1.20.3.1, 1.17.1.3 and 1.15.1.7.
A vulnerability in the public_key module of Erlang OTP, specifically in versions 19.3 prior to 26.2.5.21, 27.3.4.12, 28.5.0.1, and 29.0.1, has been identified. This vulnerability allows a DNS nameConstraints bypass by falling back on the subject CommonName during TLS hostname verification. The issue arises because the function pubkey_cert:validate_names/6 only checks Subject Alternative Name (SAN) DNS entries against nameConstraints. According to RFC 5280, a permitted DNS subtree only restricts certificates with DNS-typed names. A leaf certificate without a SAN can still satisfy any permitted DNS constraint, regardless of its CommonName. Additionally, the function public_key:pkix_verify_hostname/3 reverts to using the CommonName when no SAN is present, leading to potential misidentification of hostnames. This vulnerability could be exploited by a subordinate Certificate Authority (CA) with restricted DNS nameConstraints, allowing them to issue a certificate that the OTP TLS client mistakenly accepts for an out-of-scope hostname.
Users can update to Erlang/OTP versions 26.2.5.21, 27.3.4.12, 28.5.0.1, or 29.0.1. For those using version 19.3, a custom verify_fun can be implemented to ensure TLS connections fail if the certificate lacks a SAN extension or a valid domain name.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:39809 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:54757 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-42790 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2482286 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42790.json | redhat-SADP | |
| https://cna.erlef.org/cves/CVE-2026-42790.html | EEF | Third Party Advisory |
| https://github.com/erlang/otp/commit/0769050c69d73762672b0db1347b6993a5b31759 | EEF | Patch |
| https://github.com/erlang/otp/commit/21abed64eb2026b5f82f432709e4e932f9be389a | EEF | Patch |
| https://github.com/erlang/otp/commit/fb67c6d1836f51105a96d8b769e71e4215a79457 | EEF | Patch |
| https://github.com/erlang/otp/security/advisories/GHSA-22cw-4ph4-6447 | EEF | Vendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-42790 | EEF | MitigationThird Party Advisory |
| https://www.erlang.org/doc/system/versions.html#order-of-versions | EEF | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | redhat-SADP |
| CWE-295 | Improper Certificate Validation | EEF |
| CWE-297 | Improper Validation of Certificate with Host Mismatch | EEF |
Affected Products
| Product | Versions |
|---|---|
| erlang erlang/otp | >= 19.3, < 26.2.5.21 >= 27.0, < 27.3.4.12 >= 28.0, < 28.5.0.1 >= 29.0, < 29.0.1 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | redhat-SADP |
| Sep 18, 2026 | CVE Modified | EEF |
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Jul 24, 2026 | CVE Modified | EEF |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | EEF |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | EEF |