1sealsemantic last-mile verification

Research / Finding

AWS-LC: Unicode CommonName constraint bypass

F-AWS-LC-NAMECONSTRAINTS-002

Read the full technical write-up →

Root cause, affected code and disclosure timeline.

At a glance

Conditions
A wildcard or Unicode CommonName can bypass name constraints when hostname verification falls back to CN without a DNS name SAN.
What to do
Check the package-specific AWS advisories for fixed versions. Disabling CN fallback avoids this path; do not apply the AWS-LC version number to aws-lc-sys.

1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.

Fix and severity by source

Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
GHSA-3jrg-j22w-mpmcGHSAaws/aws-lc

AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

Fixed in: AWS-LC 1.71.0

patched
details
Finding IDs
F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
GHSA
GHSA-3jrg-j22w-mpmc
Status
patched
Fixed in
AWS-LC 1.71.0
Recorded severity
moderate
Upstream title
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

F-AWS-LC-NAMECONSTRAINTS-001: Verification failures. Wildcard common names bypass name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-LC-NAMECONSTRAINTS-001

F-AWS-LC-NAMECONSTRAINTS-002: Verification failures. Unicode common names are skipped by name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-LC-NAMECONSTRAINTS-002

Security area (1seal assessment): Identity. Wildcard common names bypass name-constraint enforcement. Unicode common names are skipped by name-constraint enforcement. Reviewed 24 Sep 2026.

—score not recorded
GHSA-394x-vwmw-crm3GHSAaws/aws-lc-rs

AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

Fixed in: aws-lc-sys 0.39.0

patched
details
Finding IDs
F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
GHSA
GHSA-394x-vwmw-crm3
Status
patched
Fixed in
aws-lc-sys 0.39.0
Recorded severity
moderate
Upstream title
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

F-AWS-LC-NAMECONSTRAINTS-001: Verification failures. Wildcard common names bypass name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-LC-NAMECONSTRAINTS-001

F-AWS-LC-NAMECONSTRAINTS-002: Verification failures. Unicode common names are skipped by name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-LC-NAMECONSTRAINTS-002

Security area (1seal assessment): Identity. Wildcard common names bypass name-constraint enforcement. Unicode common names are skipped by name-constraint enforcement. Reviewed 24 Sep 2026.

7.4high
1SEAL-2026-0021SEAL advisoryaws/aws-lc

Name Constraints bypass via CommonName fallback

Fixed in: AWS advisories: AWS-LC 1.71.0; aws-lc-sys 0.39.0

Fix recordednot counted
details
Finding IDs
F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
CVE
AWS CNA: not in scope
Status
patched
CWE
CWE-295
Fixed in
AWS advisories: AWS-LC 1.71.0; aws-lc-sys 0.39.0
Disclosure date
Recorded severity
high
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

F-AWS-LC-NAMECONSTRAINTS-001: Verification failures. Wildcard common names bypass name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-LC-NAMECONSTRAINTS-001

F-AWS-LC-NAMECONSTRAINTS-002: Verification failures. Unicode common names are skipped by name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-LC-NAMECONSTRAINTS-002

Security area (1seal assessment): Identity. Wildcard or Unicode common names bypass the certificate name constraints governing which identities the CA may certify. Reviewed 24 Sep 2026.

—score not recorded
aws/aws-lcReported fixaws/aws-lc

Fix CN fallback handling in name constraints checking

fixed publicly
details
Finding IDs
F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
Status
fixed publicly
Reported via
security contact (email)
Note
public fix in aws/aws-lc on 2026-03-19 via main commit 2aa522465f69 (#3107) and fips branch commit 35bfa4362e45 (#3108). AWS linked GHSA-3jrg-j22w-mpmc and GHSA-394x-vwmw-crm3 and said CNA scope was not met; the same PRs also close the unicode CN vector tracked as F-AWS-LC-NAMECONSTRAINTS-002.

F-AWS-LC-NAMECONSTRAINTS-001: Verification failures. Wildcard common names bypass name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-LC-NAMECONSTRAINTS-001

F-AWS-LC-NAMECONSTRAINTS-002: Verification failures. Unicode common names are skipped by name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-LC-NAMECONSTRAINTS-002

Security area (1seal assessment): Identity. Wildcard and Unicode common names bypass name-constraint enforcement. Reviewed 24 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.