The Lab · 2026-03-29 09:27:01 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a fundamental flaw in how the software validates DNS name constraints. The vulnerability, tracked as CVE-2026-34073, allowed a malicious actor to bypass critical security checks. Specifically, the library only va...
The Lab · 2026-03-31 16:27:22 · GitHub Issues
A critical security vulnerability in the widely used Python cryptography library has been disclosed, allowing for a bypass of DNS name constraints during certificate validation. The flaw, tracked as CVE-2026-34073, was present in all versions prior to 46.0.6. The core failure was that DNS name constraints were only val...
The Lab · 2026-04-14 11:22:30 · Heise Online
Eine kritische Sicherheitslücke in der weit verbreiteten Kryptografie-Bibliothek wolfSSL erlaubte es, manipulierte Zertifikate unbemerkt durchzuwinken. Diese Schwachstelle, die nun durch ein Sicherheitsupdate geschlossen wurde, hätte Angreifern ermöglichen können, verschlüsselte Verbindungen zu kompromittieren und sich...