Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

TLS hostname verification falls back to CN after SAN mismatch

CVE-2026-91769

Affected product
PHP
Severity
Medium · CVSS 4.3
Disclosed

Summary

PHP's OpenSSL streams could accept a certificate whose DNS subjectAltName did not match the requested hostname if its Common Name did. Exploitation requires a certificate trusted by the client with the target hostname in its Common Name, such as one issued in a private-PKI environment. Fixed in PHP 8.2.34, 8.3.35, 8.4.26, and 8.5.11.

Disclosure timeline

Public disclosure

Credits

Reported by christos-cantina-security and DavidKorczynski, as credited in PHP's advisory.

References