GHSA-xgp8-3hg3-c2mh
ADVISORY - githubSummary
Permitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name.
This was incorrect because, given a name constraint of accept.example.com, *.example.com could feasibly allow a name of reject.example.com which is outside the constraint.
This is very similar to CVE-2025-61727.
Since name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.
Common Weakness Enumeration (CWE)
Improper Certificate Validation
GitHub
0.7
CVSS SCORE
2.2lowRustSec
-
Chainguard
CGA-66j7-pfx4-g5hh
-
minimos
MINI-2pj3-jvw8-q8mc
-
minimos
MINI-385q-fcrf-8gr8
-
minimos
MINI-47px-xqhg-xj38
-
minimos
MINI-5c25-rg29-78cw
-
minimos
MINI-67x9-xgv8-p736
-
minimos
MINI-6f98-hpm5-8pp3
-
minimos
MINI-7mq7-prg4-xh8v
-
minimos
MINI-7r39-9h76-mwwr
-
minimos
MINI-89m9-2cg6-jvwx
-
minimos
MINI-chr9-7ggp-3r3w
-
minimos
MINI-cpr5-q7vr-r9xm
-
minimos
MINI-f9q6-grjq-7pvg
-
minimos
MINI-gfrv-mrv2-7r3p
-
minimos
MINI-h7pq-cpwx-x43m
-
minimos
MINI-h87x-wmhr-8g5g
-
minimos
MINI-j8ch-xf4f-vc54
-
minimos
MINI-pffm-2528-6m66
-
minimos
MINI-q9mx-3v56-5p5w
-