AZL-104907

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104907.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-104907
Upstream
  • CVE-2026-91769
Published
2026-09-25T21:17:24Z
Modified
2026-09-29T05:37:47Z
Summary
CVE-2026-91769 affecting package php 8.3.33-1
Details

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

References

Affected packages

Azure Linux:3 / php

Package

Name
php
Purl
pkg:rpm/azure-linux/php

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
8.3.33-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104907.json"