CVE-2026-69248: python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
If an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography’s verifier accepts which allows escaping outside of the permitted names.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-69248 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →