CVE Tools

Haskell TLS Vulnerability Lets Attackers Forge Trusted Certificates (CVE-2026-9648)

Daily CyberSecurity (securityonline.info)By Do Son

Patchcrypton-x509-validation

Our summary

A critical issue in the Haskell library crypton-x509-validation (CVE-2026-9648, CVSS 9.1) allows TLS clients to accept forged certificates because the library does not enforce X.509 NameConstraints as required by RFC 5280. This matters because it can let attackers extend trust beyond the permitted scope of a name-constrained CA, potentially enabling credential/session interception in real-world deployments, especially delegated PKI used by financial institutions. CERT/CC reports that upgrading to crypton-x509-validation version 1.9.1 is the recommended mitigation.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store