VU#862559: crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints
2026-06-11T20:52:14Z•e9a1781895e4a530dedbca04c74c14ffc8ad9e7b6ec33d9eb1fc7e79c438107b
appsmithbyovdchrome-extensioncodemirrorcollibracrypton-x509-validationdbxhaskellimsinsecure-transportipseckernel-driver','missing-acl','pctcore64','privilege-escalation',nameconstraintspath-traversalprivileged-rest-endpointssecure-bootshimsiptlsuefivolteweak-cryptox509xsszip-slip
What happened
CERT/CC published multiple advisories covering a range of high-impact vulnerabilities across diverse ecosystems. Notable issues include a Haskell TLS library failing to enforce X.509 NameConstraints (crypton-x509-validation — CVE-2026-9648) enabling certificate impersonation/MITM; Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass (will be added to DBX); multiple weaknesses in the Securly Chrome extension (insecure HTTP fetches, hardcoded AES keys, exposed endpoints — CVE-2026-8874/8876/8878/8879) that can leak or allow manipulation of sensitive configuration; Verizon IMS/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- e9a1781895e4a530dedbca04c74c14ffc8ad9e7b6ec33d9eb1fc7e79c438107b
- Enrichment time
- 2026-06-11T20:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.