CVE-2026-91769

NameCVE-2026-91769
DescriptionPHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6514-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php8.2 (PTS)bookworm8.2.32-1~deb12u1vulnerable
bookworm (security)8.2.33-1~deb12u1vulnerable
php8.4 (PTS)trixie8.4.24-1~deb13u1vulnerable
trixie (security)8.4.26-1~deb13u1fixed
forky, sid8.4.24-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php8.2source(unstable)(unfixed)
php8.4sourcetrixie8.4.26-1~deb13u1DSA-6514-1
php8.4source(unstable)(unfixed)

Notes

https://github.com/php/php-src/security/advisories/GHSA-vvx9-73fr-5jjx
https://github.com/php/php-src/blob/php-8.4.26/NEWS

Search for package or bug name: Reporting problems