Patch released crypton-x509-validation cryptography info-disclosure
Haskell TLS Vulnerability Lets Attackers Forge Trusted Certificates (CVE-2026-9648)
CVE Tools coverage
A critical issue in the Haskell library crypton-x509-validation (CVE-2026-9648, CVSS 9.1) allows TLS clients to accept forged certificates because the library does not enforce X.509 NameConstraints as required by RFC 5280. This matters because it can let attackers extend trust beyond the permitted scope of a name-constrained CA, potentially enabling credential/session interception in real-world deployments, especially delegated PKI used by financial institutions. CERT/CC reports that upgrading to crypton-x509-validation version 1.9.1 is the recommended mitigation.