Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-91769— TLS Hostname Verification Falls Back to CN After SAN Mismatch

Quick assessment

Affected
PHP Group PHP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PHP 的 OpenSSL 流对等体验证功能会优先检查证书的 subjectAltName(主题备用名称)条目;若没有任何条目匹配,则回退检查通用名(Common Name, CN)。根据 RFC 6125 的要求,一旦证书提供了任何服务身份标识(如 SAN),就应忽略 CN。然而,当证书中包含一个与请求的对等名称不匹配的 DNS 类型 SAN 条目时,若其 CN 与请求的对等名称相匹配,该证书仍会被接受。因此,客户端信任用于某一名称的证书,可能被攻击者滥用以冒充另一名称。

CVSS 4.3 · Medium EPSS 0.14% · P2

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91769

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TLS Hostname Verification Falls Back to CN After SAN Mismatch
Source: CVE Program / CVE List V5
Vulnerability Description
PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对宿主不匹配的证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PHP Group PHP 8.2.* ~ 8.2.34 -

II. Public POCs for CVE-2026-91769

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91769

请登录查看更多情报信息。

Other References for CVE-2026-91769 (1)

Same Patch Batch · PHP Group · 2026-09-25 · 11 CVEs total

CVE-2026-91765 7.5 HIGH SOAP: Unbounded Recursion in Server-Side cleanup_xml_node
CVE-2026-17545 6.9 MEDIUM PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can ca
CVE-2026-91767 6.5 MEDIUM Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard
CVE-2026-91768 6.5 MEDIUM IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm
CVE-2025-14181 6.5 MEDIUM Integer overflow to buffer overflow in soap HTTP parsing
CVE-2026-92842 5.9 MEDIUM OOB read / info leak in convert.* stream filters when line-break-chars contains NUL
CVE-2026-91766 5.9 MEDIUM Cross-origin credential leak in HTTP stream wrapper redirects
CVE-2026-93682 5.8 MEDIUM Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca
CVE-2026-6103 4.3 MEDIUM Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection
CVE-2025-1218 3.4 LOW Various packet overreads in mysqlnd_writeprotocol.c

IV. Related Vulnerabilities

V. Comments for CVE-2026-91769

No comments yet


Leave a comment