securityonline.info 6/16/2026, 3:47:21 AM · external

Haskell TLS flaw allows forged certificates, CVE-2026-9648

Haskell TLS flaw allows forged certificates, CVE-2026-9648
CyberSIXT Evidence Panel
Primary Source kb.cert.org
CISA KEV Not in KEV
Patch Patch Status Unknown

A serious vulnerability in the Haskell TLS library (CVE-2026-9648) poses risks to secure communications in finance and enterprise systems. The flaw stems from the crypton-x509-validation library's failure to enforce X.509 NameConstraints, allowing attackers to forge trusted certificates. This vulnerability has a high CVSS score of 9.1 and enables unauthorized certificate issuance, leading to potential credential theft and exposure of sensitive information. While exploitation requires significant setup, all prior library versions are affected. Users are advised to upgrade to version 1.9.1 to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT