VA-26-183-01
Vulnerability from csaf_cisa - Published: 2026-07-02 17:50 - Updated: 2026-07-21 14:32Summary
Cloudflare Universal SSL CAA record override
Notes
Legal Notice: All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).
Countries and Areas Deployed: Worldwide
Critical Infrastructure Sectors: Information Technology
Risk Evaluation: Cloudflare Universal SSL automatically manages the CAA RRset for customer zones in order to issue and renew TLS certificates. In affected Universal SSL configurations, Cloudflare authoritative DNS can serve an auto-managed CAA RRset at query time that supersedes customer-configured CAA records. As a result, Certificate Authorities may not observe customer-configured RFC 8657 accounturi or validationmethods parameters when evaluating CAA under RFC 8659. Customers may therefore believe strict certificate-issuance controls are enforced, while those controls are not preserved end-to-end for Universal SSL zones. Successful exploitation is non-trivial and requires a strong network position plus successful domain validation, but misissuance could result in a browser-trusted TLS certificate and enable MITM against the affected domain.
Recommended Practices: Certificate Transparency monitoring is recommended as a detection control for misissued browser-trusted certificates. It does not prevent certificate issuance and should not be treated as a preventive mitigation for strict RFC 8657 enforcement.
Company Headquarters Location: United States
References
12 references
{
"document": {
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE"
}
},
"lang": "en-US",
"notes": [
{
"category": "legal_disclaimer",
"text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).",
"title": "Legal Notice"
},
{
"category": "other",
"text": "Worldwide",
"title": "Countries and Areas Deployed"
},
{
"category": "other",
"text": "Information Technology",
"title": "Critical Infrastructure Sectors"
},
{
"category": "summary",
"text": "Cloudflare Universal SSL automatically manages the CAA RRset for customer zones in order to issue and renew TLS certificates. In affected Universal SSL configurations, Cloudflare authoritative DNS can serve an auto-managed CAA RRset at query time that supersedes customer-configured CAA records. As a result, Certificate Authorities may not observe customer-configured RFC 8657 accounturi or validationmethods parameters when evaluating CAA under RFC 8659. Customers may therefore believe strict certificate-issuance controls are enforced, while those controls are not preserved end-to-end for Universal SSL zones. Successful exploitation is non-trivial and requires a strong network position plus successful domain validation, but misissuance could result in a browser-trusted TLS certificate and enable MITM against the affected domain.",
"title": "Risk Evaluation"
},
{
"category": "general",
"text": "Certificate Transparency monitoring is recommended as a detection control for misissued browser-trusted certificates. It does not prevent certificate issuance and should not be treated as a preventive mitigation for strict RFC 8657 enforcement.",
"title": "Recommended Practices"
},
{
"category": "other",
"text": "United States",
"title": "Company Headquarters Location"
}
],
"publisher": {
"category": "coordinator",
"contact_details": "https://www.cisa.gov/report",
"issuing_authority": "CISA",
"name": "CISA",
"namespace": "https://www.cisa.gov/"
},
"references": [
{
"category": "self",
"summary": "Vulnerability Advisory VA-26-183-01 CSAF",
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-183-01.json"
}
],
"title": "Cloudflare Universal SSL CAA record override",
"tracking": {
"current_release_date": "2026-07-21T14:32:00Z",
"generator": {
"engine": {
"name": "VINCE-NT",
"version": "1.15.0+build.101"
}
},
"id": "VA-26-183-01",
"initial_release_date": "2026-07-02T17:50:36Z",
"revision_history": [
{
"date": "2026-07-21T14:32:00Z",
"number": "2.0.1",
"summary": "Version history correction"
},
{
"date": "2026-07-07T00:00:00Z",
"number": "2.0.0",
"summary": "Edited summary, mitigation and recommended practices"
},
{
"date": "2026-07-02T17:50:36Z",
"number": "1.0.0",
"summary": "Initial publication"
}
],
"status": "final",
"version": "2.0.1"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "vers:all/*",
"product": {
"name": "Cloudflare Universal SSL vers:all/*",
"product_id": "CSAFPID-0001"
}
}
],
"category": "product_name",
"name": "Universal SSL"
}
],
"category": "vendor",
"name": "Cloudflare"
}
]
},
"vulnerabilities": [
{
"acknowledgments": [
{
"names": [
"David Osipov"
]
}
],
"cve": "CVE-2026-14440",
"cwe": {
"id": "CWE-693",
"name": "Protection Mechanism Failure"
},
"notes": [
{
"category": "summary",
"text": "Cloudflare Universal SSL adds Certification Authority Authorization (CAA) DNS records that override user-configured CAA records. The Universal SSL CAA records may be more permissive than user-configured records, for example, overriding the RFC 8657 \u0027accounturi\u0027 parameter. An attacker with appropriate network access may be able to spoof domain validation and obtain a certificate for the target domain.",
"title": "Description"
},
{
"category": "details",
"text": "SSVCv2/E:P/A:N/T:T/2026-05-18T17:12:47Z/",
"title": "SSVC"
}
],
"product_status": {
"known_affected": [
"CSAFPID-0001"
]
},
"references": [
{
"category": "external",
"summary": "developers.cloudflare.com",
"url": "https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/"
},
{
"category": "external",
"summary": "www.rfc-editor.org",
"url": "https://www.rfc-editor.org/rfc/rfc8657.html"
},
{
"category": "external",
"summary": "www.rfc-editor.org",
"url": "https://www.rfc-editor.org/rfc/rfc8659.html"
},
{
"category": "external",
"summary": "david-osipov.vision",
"url": "https://david-osipov.vision/en/blog/cybersecurity/cloudflare-ssl-mitm-flaw-2026/"
},
{
"category": "external",
"summary": "community.cloudflare.com",
"url": "https://community.cloudflare.com/t/critical-security-gap-cloudflare-must-fully-support-rfc-8657-caa/799999/10"
},
{
"category": "external",
"summary": "community.cloudflare.com",
"url": "https://community.cloudflare.com/t/universal-ssl-exposes-domains-to-bgp-leaks-re-venezuela-analysis/879930"
},
{
"category": "external",
"summary": "zenodo.org",
"url": "https://zenodo.org/records/18330221"
},
{
"category": "external",
"summary": "developers.cloudflare.com",
"url": "https://developers.cloudflare.com/ssl/edge-certificates/caa-records/"
},
{
"category": "external",
"summary": "developers.cloudflare.com",
"url": "https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/limitations/"
},
{
"category": "external",
"summary": "CVE-2026-14440",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-14440"
},
{
"category": "external",
"summary": "VA-26-183-01",
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-183-01.json"
}
],
"release_date": "2025-05-20T00:00:00Z",
"remediations": [
{
"category": "mitigation",
"date": "2026-07-01T00:00:00Z",
"details": "Customers requiring strict RFC 8657 accounturi or validationmethods enforcement should disable Universal SSL on the affected zone only after ensuring that another valid Cloudflare edge certificate is active, such as an Advanced Certificate or uploaded Custom Certificate. Without an alternative active edge certificate, disabling Universal SSL can break HTTPS for new connections.",
"product_ids": [
"CSAFPID-0001"
],
"url": "https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/disable-universal-ssl/"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-0001"
]
}
],
"title": "Cloudflare Universal SSL CAA record override"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…