x509-validator is vulnerable to Improper Certificate Validation
74
High Risk
The iPAddress exclusion check treats an excluded_subtrees constraint whose mask is all zeros (0.0.0.0/0 or ::/0) as matching nothing. A /0 prefix matches every address of that family, so the exclusion is ignored. A technically constrained sub-CA that must not issue for IP addresses can still issue a certificate for an arbitrary IP, and Validator with RFC5280Policy and ServerIdentityPolicy accepts it for that address. A permitted_subtrees dNSName entry on the same issuer does not stop this, because an iPAddress SAN is a different name form. The fix treats an all-zero mask as matching every address of its family.
You are affected if you are using a version that falls within the vulnerable range and you validate chains with Validator and RFC5280Policy that can include a name-constrained issuer with an all-zero iPAddress exclusion.
x509-validator is vulnerable to Improper Certificate Validation in versions 0.1.0 - 0.3.0.
Upgrade the x509-validator library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.