Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-91769

8 дней назад

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2026-91769

8 дней назад

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-91769

8 дней назад

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2026-91769

5 дней назад

TLS Hostname Verification Falls Back to CN After SAN Mismatch

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-91769

8 дней назад

PHP's OpenSSL stream peer verification checks the certificate's subjec ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vvx9-73fr-5jjx

9 дней назад

TLS Hostname Verification Falls Back to CN After SAN Mismatch

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-91769

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

CVSS3: 4.3
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-91769

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

CVSS3: 4.3
0%
Низкий
8 дней назад
nvd логотип
CVE-2026-91769

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

CVSS3: 4.3
0%
Низкий
8 дней назад
msrc логотип
CVE-2026-91769

TLS Hostname Verification Falls Back to CN After SAN Mismatch

CVSS3: 4.3
0%
Низкий
5 дней назад
debian логотип
CVE-2026-91769

PHP's OpenSSL stream peer verification checks the certificate's subjec ...

CVSS3: 4.3
0%
Низкий
8 дней назад
github логотип
GHSA-vvx9-73fr-5jjx

TLS Hostname Verification Falls Back to CN After SAN Mismatch

CVSS3: 4.3
0%
Низкий
9 дней назад

Уязвимостей на страницу