CVE WATCH / VULNERABILITY DETAIL

CVE-2026-91767

MEDIUMCVSS 6.5NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-91767 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-91767

MEDIUMCVSS 6.5NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]