WhisperX tag archive

#TLS/SSL

This page collects WhisperX intelligence signals tagged #TLS/SSL. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-03-29 09:27:01 · GitHub Issues

1. Critical Cryptography Library Flaw: CVE-2026-34073 Bypasses DNS Name Constraint Validation

A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a fundamental flaw in how the software validates DNS name constraints. The vulnerability, tracked as CVE-2026-34073, allowed a malicious actor to bypass critical security checks. Specifically, the library only va...

The Lab · 2026-03-31 16:27:22 · GitHub Issues

2. Cryptography Library Vulnerability: DNS Name Constraint Bypass in Versions <46.0.6

A critical security vulnerability in the widely used Python cryptography library has been disclosed, allowing for a bypass of DNS name constraints during certificate validation. The flaw, tracked as CVE-2026-34073, was present in all versions prior to 46.0.6. The core failure was that DNS name constraints were only val...

The Lab · 2026-04-14 11:22:30 · Heise Online

3. Kritische Lücke in wolfSSL: Bibliothek akzeptierte manipulierte Zertifikate

Eine kritische Sicherheitslücke in der weit verbreiteten Kryptografie-Bibliothek wolfSSL erlaubte es, manipulierte Zertifikate unbemerkt durchzuwinken. Diese Schwachstelle, die nun durch ein Sicherheitsupdate geschlossen wurde, hätte Angreifern ermöglichen können, verschlüsselte Verbindungen zu kompromittieren und sich...