CVE-2026-9648 Details
Description
The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope.
A vulnerability exists in the Crypton X.509 Validation Haskell library, specifically in versions prior to 1.9.1. The library fails to properly enforce X.509 NameConstraints, which are crucial for controlling the domains a certificate authority (CA) can issue certificates for. This oversight allows TLS clients to accept certificates with Subject Alternative Names (SANs) that fall outside the CA's permitted subtrees. Consequently, an attacker who compromises a name-constrained sub-CA could impersonate domains beyond the CA's intended scope, potentially intercepting sensitive data from Haskell clients.
Users of the Crypton X.509 Validation library should update to version 1.9.1, as all prior versions are vulnerable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 11, 2026CISA-ADP
Assessed Jun 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| crypton-x509-validation | < 1.9.1 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | [email protected] |
| Jun 11, 2026 | CVE Modified | CVE |
Volerion