VU#862559: crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints

2026-06-16T08:52:11Z0b986993c570e477ba94df519e3fa23036e26fdd18fc685e537ab4b3f09a6c87
AppsmithBYOVDChrome extensionCodeMirrorDBXHaskellIMSIPsecNameConstraintsSIPSQL-autocompleteSecure BootSecurlyTLSUEFIVoLTEaccess-controlcrypton-x509-validationhardcoded-keysintegrity-protectionshimstored-XSSunencrypted-transportweak-cryptographyx509

What happened

CERT/CC vulnerability notes covering multiple distinct high-impact issues: (1) crypton-x509-validation (Haskell) fails to enforce X.509 NameConstraints allowing name-constrained sub-CAs to issue certs outside permitted scope (CVE-2026-9648; fixed in crypton-x509-validation 1.91). (2) Microsoft-signed shim UEFI bootloaders (≤0.9) vulnerable to Secure Boot bypass via BYOVD techniques; affected shims will be added to Microsoft DBX. (3) Securly Chrome Extension (v3.0.7) exposes insecure HTTP fetches, hardcoded AES passphrases, and unauthenticated endpoints leading to data exposure and manipulation

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
0b986993c570e477ba94df519e3fa23036e26fdd18fc685e537ab4b3f09a6c87
Enrichment time
2026-06-16T08:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.