From: NotCVE Advisories <advisories () notcve org>
Date: Mon, 13 Jul 2026 13:10:43 -0000
----------------------------------------------------------------------------
NotCVE Disclosure Update — NotCVE-2026-0001 / CVE-2026-14440
----------------------------------------------------------------------------
[-] Summary:
On 2026-01-19 the issue described below was published as NotCVE-2026-0001
after no CVE identifier was assigned for it. On 2026-07-01 — 163 days
later — Cloudflare assigned CVE-2026-14440 to the same issue, now rated
CVSS 9.1. This message documents the disclosure timeline for the public
record.
[-] Affected:
Cloudflare Universal SSL (managed CAA record augmentation) — service-side
behaviour; no customer-side patch applicable.
[-] Technical Description:
Cloudflare Universal SSL automatically adds CAA issue/issuewild records
when a customer has Universal SSL enabled and publishes any CAA records
for the zone. These auto-added records are not shown in the Cloudflare
dashboard but are returned in DNS responses, and can include permissive
authorizations such as:
CAA 0 issue "letsencrypt.org"
CAA 0 issuewild "letsencrypt.org"
When a domain owner uses RFC 8657 CAA extensions (accounturi and/or
validationmethods) to restrict certificate issuance to a specific
authorized ACME account or validation method, the presence of an
auto-added CAA issue property WITHOUT those RFC 8657 constraints broadens
authorization: per RFC 8657, a CAA property without an accounturi
parameter matches any account. This weakens the domain owner's intended
account binding and may enable unauthorized DV certificate issuance.
[-] Disclosure Timeline:
[19/01/2026] - Public record published as NotCVE-2026-0001; no CVE
identifier assigned at that time
[01/07/2026] - Cloudflare assigns CVE-2026-14440 (CVSS 9.1) for the same
issue, 163 days after the public record
[-] CVE Reference:
CVE-2026-14440
[-] References:
https://notcve.org/notcve/NotCVE-2026-0001 (full technical record,
preserved since day one)
https://notcve.org/cve/CVE-2026-14440
[-] About NotCVE:
NotCVE (https://notcve.org) assigns public, timestamped NotCVE IDs to
vulnerabilities not acknowledged by vendors. Vendor will not assign a CVE?
Request a NotCVE: https://notcve.org/form/ · Contributors:
https://notcve.org/hall/
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- [NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure NotCVE Advisories (Jul 15)