4.3

CVE-2026-91769

TLS Hostname Verification Falls Back to CN After SAN Mismatch

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPHP Group
≫
Produkt PHP
Default Statusunaffected
Version 8.2.*
Version < 8.2.34
Status affected
Version 8.3.*
Version < 8.3.35
Status affected
Version 8.4.*
Version < 8.4.26
Status affected
Version 8.5.*
Version < 8.5.11
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
PHP 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-297 Improper Validation of Certificate with Host Mismatch

The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.

https://github.com/php/php-src/security/advisories/GHSA-vvx9-73fr-5jjx