CVE-2026-69248

EUVD-2026-52448
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.35%
Debian logo
Debian Releases
Debian Product
Codename
python-cryptography
bookworm
vulnerable
bookworm (security)
vulnerable
forky
49.0.0-2
fixed
sid
49.0.0-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-cryptography
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
Fixed 46.0.5-1ubuntu2.2
released
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
python3.14-cryptography
RHEL 9
0:45.0.4-4.el9_8.6
fixed