Improper validation of certificate with host mismatch in LibreSSL - #VU153345
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass hostname mismatch detection.
The vulnerability exists due to incomplete reporting of hostname mismatches in certificate verification callbacks when verifying a peer hostname. A remote attacker can present a certificate with a mismatched hostname to bypass hostname mismatch detection.
The issue concerns verification callbacks that always return 1.