threat_intelligence352 wordsRead on Arc Codex

[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding β€” CVE-2026-14440 assigned 163 days after public no

Full Disclosure mailing list archives [NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding β€” CVE-2026-14440 assigned 163 days after public no-CVE disclosure From: NotCVE Advisories Date: Mon, 13 Jul 2026 13:10:43 -0000 ---------------------------------------------------------------------------- NotCVE Disclosure Update β€” NotCVE-2026-0001 / CVE-2026-14440 ---------------------------------------------------------------------------- [-] Summary: On 2026-01-19 the issue described below was published as NotCVE-2026-0001 after no CVE identifier was assigned for it. On 2026-07-01 β€” 163 days later β€” Cloudflare assigned CVE-2026-14440 to the same issue, now rated CVSS 9.1. This message documents the disclosure timeline for the public record. [-] Affected: Cloudflare Universal SSL (managed CAA record augmentation) β€” service-side behaviour; no customer-side patch applicable. [-] Technical Description: Cloudflare Universal SSL automatically adds CAA issue/issuewild records when a customer has Universal SSL enabled and publishes any CAA records for the zone. These auto-added records are not shown in the Cloudflare dashboard but are returned in DNS responses, and can include permissive authorizations such as: CAA 0 issue "letsencrypt.org" CAA 0 issuewild "letsencrypt.org" When a domain owner uses RFC 8657 CAA extensions (accounturi and/or validationmethods) to restrict certificate issuance to a specific authorized ACME account or validation method, the presence of an auto-added CAA issue property WITHOUT those RFC 8657 constraints broadens authorization: per RFC 8657, a CAA property without an accounturi parameter matches any account. This weakens the domain owner's intended account binding and may enable unauthorized DV certificate issuance. [-] Disclosure Timeline: [19/01/2026] - Public record published as NotCVE-2026-0001; no CVE identifier assigned at that time [01/07/2026] - Cloudflare assigns CVE-2026-14440 (CVSS 9.1) for the same issue, 163 days after the public record [-] CVE Reference: CVE-2026-14440 [-] References: https://notcve.org/notcve/NotCVE-2026-0001 (full technical record, preserved since day one) https://notcve.org/cve/CVE-2026-14440 [-] About NotCVE: NotCVE (https://notcve.org) assigns public, timestamped NotCVE IDs to vulnerabilities not acknowledged by vendors. Vendor will not assign a CVE? Request a NotCVE: https://notcve.org/form/ Β· Contributors: https://notcve.org/hall/ _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/ Current thread: - [NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding β€” CVE-2026-14440 assigned 163 days after public no-CVE disclosure NotCVE Advisories (Jul 15)

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content β€” general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached β€” you'll always get the same 5 for this article.