VDB
GCVE-110-HSEC-2026-0008-2
GCVE-110-HSEC-2026-0008-2
Advisory PublishedCVSS 6.8/10
# crypton-x509-validation and crypton-x509 do not enforce X.509 Name Constraints
The `crypton-x509-validation` and `crypton-x509` libraries did not
enforce the X.509 Name Constraints extension during certificate
validation. The Name Constraints extension is a critical X.509
extension that restricts the namespace (permitted and excluded
subtrees) for which a CA is authorized to issue certificates.
Without this enforcement, a TLS client would accept certificates with
Subject Alternative Names (SANs) that fall outside the issuing CA's
permitted subtrees. An attacker with access to a name-constrained
sub-CA's private key could therefore issue certificates for domains
outside the sub-CA's intended scope, enabling impersonation of
arbitrary domains and man-in-the-middle attacks on TLS connections.
The older `x509` and `x509-validation` packages are also affected but
are no longer maintained and have no fix available.
This issue was fixed in `crypton-x509-validation-1.9.1` and
`crypton-x509-1.9.1`.
Weaknesses (CWE)
CWE-295CWE-295
Risk Scores
CVSS 3.1
6.8/10
Medium · CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| haskell | crypton-x509 | 1.7.6 (affected) | — |
Browse GCVE Records
74,355 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.