CVE-2026-91769

Published: September 26, 2026Last modified: September 26, 2026

Description

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

Severity score breakdown

ParameterValue
Base score4.3
Attack VectorADJACENT_NETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSphp81Unknown (8.1.19-r0)
25 LTSphp83Fixed (8.3.35-r0)
Streamphp83Fixed (8.3.35-r0)

References

ON THIS PAGE