Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verific…
Summary
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. permitted;DNS:allowed.example.com) to issue a leaf certificate that an OTP TLS client accepts as a valid identity for an out-of-scope hostname (e.g. victim.example.com): First, pubkey_cert:validate_na…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Lint boundary warnings (1)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://www.erlang.org/doc/system/versions.html#order-of-versions
Sources
- NVD DATABASE
Original Links
- https://cna.erlef.org/cves/CVE-2026-42790.html Third Party Advisory
- https://github.com/erlang/otp/commit/0769050c69d73762672b0db1347b6993a5b31759 Patch
- https://github.com/erlang/otp/commit/21abed64eb2026b5f82f432709e4e932f9be389a Patch
- https://github.com/erlang/otp/commit/fb67c6d1836f51105a96d8b769e71e4215a79457 Patch
- https://github.com/erlang/otp/security/advisories/GHSA-22cw-4ph4-6447 Vendor Advisory
- https://osv.dev/vulnerability/EEF-CVE-2026-42790 Mitigation
- https://www.erlang.org/doc/system/versions.html#order-of-versions Product
- https://access.redhat.com/errata/RHSA-2026:39809
- https://access.redhat.com/security/cve/CVE-2026-42790
- https://bugzilla.redhat.com/show_bug.cgi?id=2482286
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42790.json
Timeline
- nvd_ingest NVD