VU#862559: crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints
2026-06-16T08:52:11Z•0b986993c570e477ba94df519e3fa23036e26fdd18fc685e537ab4b3f09a6c87
AppsmithBYOVDChrome extensionCodeMirrorDBXHaskellIMSIPsecNameConstraintsSIPSQL-autocompleteSecure BootSecurlyTLSUEFIVoLTEaccess-controlcrypton-x509-validationhardcoded-keysintegrity-protectionshimstored-XSSunencrypted-transportweak-cryptographyx509
What happened
CERT/CC vulnerability notes covering multiple distinct high-impact issues: (1) crypton-x509-validation (Haskell) fails to enforce X.509 NameConstraints allowing name-constrained sub-CAs to issue certs outside permitted scope (CVE-2026-9648; fixed in crypton-x509-validation 1.91). (2) Microsoft-signed shim UEFI bootloaders (≤0.9) vulnerable to Secure Boot bypass via BYOVD techniques; affected shims will be added to Microsoft DBX. (3) Securly Chrome Extension (v3.0.7) exposes insecure HTTP fetches, hardcoded AES passphrases, and unauthenticated endpoints leading to data exposure and manipulation
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 0b986993c570e477ba94df519e3fa23036e26fdd18fc685e537ab4b3f09a6c87
- Enrichment time
- 2026-06-16T08:52:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.