THREAT OPS › Threat News › [GHSA] GHSA-m2h6-j472-rp4c (medium) — python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
[GHSA] GHSA-m2h6-j472-rp4c (medium) — python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
GHSA-m2h6-j472-rp4c Severity: medium CVE: CVE-2026-69248
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
### Summary If an intermediate constrained CA permits the DNS name `foo.example.com`, and the leaf certificate has a wildcard in its DNS SAN of `*.example.com`, python-cryptography's verifier accepts which allows escaping outside of the permitted
Indicators of compromise
- CVE-2026-69248cve
- 4.2.1.10ipv4
Original source: https://github.com/advisories/GHSA-m2h6-j472-rp4c