Executive brief
The crypton-x509-validation library, a component used by Haskell applications to establish secure internet connections, fails to properly verify certificate restrictions. This flaw allows an attacker who controls a restricted sub-authority to create fraudulent digital certificates for any domain. If exploited, an attacker could intercept sensitive data, steal credentials, or impersonate trusted services when a Haskell-based application connects to them.
Technical details
The crypton-x509-validation library fails to implement NameConstraints enforcement as defined in RFC 5280. During the certificate validation process, the library does not verify if the Subject Alternative Name (SAN) of a leaf certificate resides within the permitted subtrees defined by a name-constrained intermediate CA. An attacker possessing the private key of a constrained sub-CA can issue certificates for unauthorized domains that Haskell TLS clients will incorrectly trust. This enables man-in-the-middle (MitM) attacks and domain impersonation. The issue is resolved in version 1.9.1.
Affected products
- Haskell crypton-x509-validation < 1.9.1
Timeline
- 2026-05-18: other: Initial fix commits authored
- 2026-05-20: other: Vendor notified
- 2026-06-03: patched: Version 1.9.1 released on Hackage
- 2026-06-11: disclosed: CVE published and CERT/CC advisory released
References
- https://github.com/haskell/security-advisories/pull/332
- https://github.com/kazu-yamamoto/crypton-certificate/pull/30
- https://github.com/kazu-yamamoto/crypton-certificate/pull/30/changes/f4b77edf6ead77f4a886da40e41eab20f0180e39
- https://hackage.haskell.org/package/crypton-x509-validation-1.9.1/revisions/
- https://www.kb.cert.org/vuls/id/862559