Research / Finding
X.509: bypass of name constraints on wildcard SANs with matching peer names F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
—score not recorded
X.509: bypass of name constraints on wildcard SANs with matching peer names
Fixed in: >= 46.0.6
patched
details
Finding IDs F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001 CVE CVE-2026-34073 GHSA GHSA-m959-cc7f-wv43 Status patched Fixed in >= 46.0.6 Recorded credit Reporter: 1seal Note inferred mapping CVE registry state PUBLISHED CVE state checked 23 Sep 2026 Upstream title X.509: bypass of name constraints on wildcard SANs with matching peer names Upstream CWE CWE-295 Upstream publication 25 Mar 2026 Upstream updated 25 Mar 2026 Metadata fetched 23 Sep 2026 Upstream @1seal credit @1seal: reporter (accepted) F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001: Verification failures. Wildcard DNS names bypass certificate name constraints. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001
Security area (1seal assessment): Identity. Wildcard DNS names bypass certificate name constraints. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .