AI description
CVE-2026-91769 describes a vulnerability within OpenSSL's TLS hostname verification process, specifically as it pertains to PHP. The issue arises when the system incorrectly falls back to verifying the common name (CN) in a TLS certificate, even after a mismatch has been detected with the subject alternative name (SAN). This flaw, identified as "TLS hostname verification falls back to CN after SAN mismatch," has been addressed in PHP. Users are advised to upgrade to PHP version 8.3.35 or later to mitigate this vulnerability.
- Description
- PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.
- Source
- security@php.net
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- security@php.net
- CWE-297
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
13
PHP 8.4.26 released - 64 fixes in 25 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/ZrPmRpxg1x
@php_net
26 Sept 2026
4420 Impressions
10 Retweets
47 Likes
5 Bookmarks
0 Replies
1 Quote
CVE-2026-91769 PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 r… https://t.co/f6I78KoeJ6
@CVEnew
26 Sept 2026
176 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PHP 8.2.34 released - 12 fixes in 8 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/Or4opPr46m
@php_net
25 Sept 2026
4236 Impressions
4 Retweets
22 Likes
1 Bookmark
0 Replies
0 Quotes
PHP 8.3.35 released - 12 fixes in 8 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/V3HAM01AXX
@php_net
25 Sept 2026
3811 Impressions
6 Retweets
28 Likes
3 Bookmarks
0 Replies
0 Quotes
PHP 8.5.11 released - 57 fixes in 22 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/sJtYkJM8Hd
@php_net
24 Sept 2026
4391 Impressions
13 Retweets
47 Likes
7 Bookmarks
0 Replies
0 Quotes