CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69248

unknowncovered by 1 sourcefirst seen 2026-08-03
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.

⚡ Watch CVE-2026-69248

Get an email if CVE-2026-69248 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-69248

CVE.org record

Embed the live status

CVE-2026-69248 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69248 status](https://www.csirts.com/badge/CVE-2026-69248)](https://www.csirts.com/cve/CVE-2026-69248)