Improper Certificate Validation in python-cryptography - CVE-2026-34073
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate name constraints validation.
The vulnerability exists due to improper certificate validation in the X.509 certificate validation logic when validating a peer name against a wildcard SAN certificate chain. A remote attacker can present a crafted certificate chain to bypass certificate name constraints validation.
Exploitation requires an uncommon X.509 topology involving an excluded subtree constraint that matches the peer name.
Affected software
Python for Scientific Computing
IBM Cloud Pak for Data System
z/Transaction Processing Facility ( z/TPF)
PowerVC
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
Storage Sentinel Anomaly Scan Engine
Maximo Application Suite - Predict Component
Maximo Application Suite - Visual Inspection Component
Storage Protect Plus File Systems Agent
Storage Protect Plus Guest Applications
QRadar App SDK
Maximo Scheduler Optimizer
Fedora
python-cryptography
How to mitigate CVE-2026-34073
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4
Python for Scientific Computing - update to 4.3.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Maximo Application Suite - Predict Component - addressed in versions 8.8.15, 8.9.17, 9.0.14, 9.1.7
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.20, 9.1.18
Storage Protect Plus File Systems Agent - update to 10.1.19
Storage Protect Plus Guest Applications - update to 10.1.19
QRadar App SDK - update to 2.2.5
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
python-cryptography - addressed in versions 46.0.6-1.fc43, 46.0.6-1.fc44
External References
Related Security Bulletins
- Improper Certificate Validation in python-cryptography
- Fedora 44 update for python-cryptography
- Fedora 43 update for python-cryptography
- IBM z/Transaction Processing Facility update for cryptography
- IBM Maximo Application Suite - Predict Component update for cryptography
- IBM Watson Discovery Cartridge update for cryptography
- IBM Maximo Scheduler Optimizer update for cryptography
- Multiple vulnerabilities in IBM Cloud Pak for Data System
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Splunk Python for Scientific Computing update for third-party components
- Multiple vulnerabilities in IBM QRadar App SDK
- IBM PowerVC update for cryptography
- Multiple vulnerabilities in IBM Maximo Application Suite - Visual Inspection Component
- Multiple vulnerabilities in IBM Storage Protect Plus
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine