REDHAT-BUG-2503636: Medium severity OpenJDK OpenJDK vulnerability

Published Jul 21, 2026
·
Updated

OpenJDK can apply two different security meanings to the same wildcard dNSName SAN across certificate policy enforcement and hostname verification. During path validation, DNSName.constrains compares .foo.com and secret.foo.com literally and returns NAMESAMETYPE, so NameConstraintsExtension.verify does not reject the chain when secret.foo.com is an exact-host exclusion. Later, HostnameChecker interprets the same SAN as a wildcard template and accepts secret.foo.com for .foo.com.

Affected Software

1 affected component
OpenJDK OpenJDK

Event History

Jul 21, 2026
Data Sourced
via Red Hat·01:35 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2503636?

The severity of REDHAT-BUG-2503636 is medium, rated at 4.

2

What does REDHAT-BUG-2503636 affect?

REDHAT-BUG-2503636 affects OpenJDK and its handling of wildcard DNS names during certificate validation.

3

How do I fix REDHAT-BUG-2503636?

To fix REDHAT-BUG-2503636, you should apply the recommended security updates provided in the errata.

4

What is the risk associated with REDHAT-BUG-2503636?

The risk associated with REDHAT-BUG-2503636 is rated at 19, indicating a moderate potential for impact.

5

What security issues does REDHAT-BUG-2503636 highlight?

REDHAT-BUG-2503636 highlights the conflicting security interpretations of wildcard dNSName SAN in certificate policy enforcement and hostname verification.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203