Improper handling of exceptional conditions in LibreSSL - #VU153351
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to prevent verification callbacks from observing a hostname mismatch.
The vulnerability exists due to improper error reporting in certificate verification callback handling when processing a certificate with a hostname mismatch. A remote attacker can present a certificate with a mismatched hostname to prevent verification callbacks from observing a hostname mismatch.
The issue concerns verification callbacks that always return 1.