THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m2h6-j472-rp4c (medium) — python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

[GHSA] GHSA-m2h6-j472-rp4c (medium) — python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

medgithub_advisoriesPublished 2026-08-03

GHSA-m2h6-j472-rp4c Severity: medium CVE: CVE-2026-69248

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

### Summary If an intermediate constrained CA permits the DNS name `foo.example.com`, and the leaf certificate has a wildcard in its DNS SAN of `*.example.com`, python-cryptography's verifier accepts which allows escaping outside of the permitted

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m2h6-j472-rp4c