4.3
CVE-2026-91769
- EPSS 0.14%
- Veröffentlicht 25.09.2026 20:59:39
- Zuletzt bearbeitet 29.09.2026 21:27:41
- Erkennungen
TLS Hostname Verification Falls Back to CN After SAN Mismatch
PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPHP Group
≫
Produkt
PHP
Default Statusunaffected
Version
8.2.*
Version <
8.2.34
Status
affected
Version
8.3.*
Version <
8.3.35
Status
affected
Version
8.4.*
Version <
8.4.26
Status
affected
Version
8.5.*
Version <
8.5.11
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.025 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| PHP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-297 Improper Validation of Certificate with Host Mismatch
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
https://github.com/php/php-src/security/advisories/GHSA-vvx9-73fr-5jjx