GHSA-3248-8mh4-pcmrHigh

Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of...

Published
October 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen subjectAltName URIs from such a CA, to bypass permitted or excluded uniformResourceIdentifier name constraints during certification path validation via a URI whose path, query, fragment or userinfo contains characters such as '@' or ':', because the host was extracted by string slicing without first isolating the RFC 3986 authority component, so the host compared against the constraints could differ from the URI's actual host.

🔗 References (4)