All CVEs
Vulnerability intelligence

CVE-2026-9648

Haskell Programming Language crypton-certificate

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope.

CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.2%
Riskier than 13% of all CVEs · checked 2026-09-13
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Jun 16, 2026 · latest Jun 16, 2026

Coverage timeline