Improper Certificate Validation in python-cryptography - CVE-2026-34073
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate name constraints validation.
The vulnerability exists due to improper certificate validation in the X.509 certificate validation logic when validating a peer name against a wildcard SAN certificate chain. A remote attacker can present a crafted certificate chain to bypass certificate name constraints validation.
Exploitation requires an uncommon X.509 topology involving an excluded subtree constraint that matches the peer name.
Affected software
Python for Scientific Computing
IBM Cloud Pak for Data System
z/Transaction Processing Facility ( z/TPF)
PowerVC
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
Maximo Application Suite - Predict Component
QRadar App SDK
Maximo Scheduler Optimizer
Fedora
python-cryptography
How to mitigate CVE-2026-34073
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4
Python for Scientific Computing - update to 4.3.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Maximo Application Suite - Predict Component - addressed in versions 8.8.15, 8.9.17, 9.0.14, 9.1.7
QRadar App SDK - update to 2.2.5
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
python-cryptography - addressed in versions 46.0.6-1.fc43, 46.0.6-1.fc44
External References
Related Security Bulletins
- Improper Certificate Validation in python-cryptography
- Fedora 44 update for python-cryptography
- Fedora 43 update for python-cryptography
- IBM z/Transaction Processing Facility update for cryptography
- IBM Maximo Application Suite - Predict Component update for cryptography
- IBM Watson Discovery Cartridge update for cryptography
- IBM Maximo Scheduler Optimizer update for cryptography
- Multiple vulnerabilities in IBM Cloud Pak for Data System
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Splunk Python for Scientific Computing update for third-party components
- Multiple vulnerabilities in IBM QRadar App SDK
- IBM PowerVC update for cryptography