Full Disclosure mailing list archives
[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure
From: NotCVE Advisories
Date: Mon, 13 Jul 2026 13:10:43 -0000
---------------------------------------------------------------------------- NotCVE Disclosure Update — NotCVE-2026-0001 / CVE-2026-14440 ---------------------------------------------------------------------------- [-] Summary: On 2026-01-19 the issue described below was published as NotCVE-2026-0001 after no CVE identifier was assigned for it. On 2026-07-01 — 163 days later — Cloudflare assigned CVE-2026-14440 to the same issue, now rated CVSS 9.1. This message documents the disclosure timeline for the public record. [-] Affected: Cloudflare Universal SSL (managed CAA record augmentation) — service-side behaviour; no customer-side patch applicable. [-] Technical Description: Cloudflare Universal SSL automatically adds CAA issue/issuewild records when a customer has Universal SSL enabled and publishes any CAA records for the zone. These auto-added records are not shown in the Cloudflare dashboard but are returned in DNS responses, and can include permissive authorizations such as: CAA 0 issue "letsencrypt.org" CAA 0 issuewild "letsencrypt.org" When a domain owner uses RFC 8657 CAA extensions (accounturi and/or validationmethods) to restrict certificate issuance to a specific authorized ACME account or validation method, the presence of an auto-added CAA issue property WITHOUT those RFC 8657 constraints broadens authorization: per RFC 8657, a CAA property without an accounturi parameter matches any account. This weakens the domain owner's intended account binding and may enable unauthorized DV certificate issuance. [-] Disclosure Timeline: [19/01/2026] - Public record published as NotCVE-2026-0001; no CVE identifier assigned at that time [01/07/2026] - Cloudflare assigns CVE-2026-14440 (CVSS 9.1) for the same issue, 163 days after the public record [-] CVE Reference: CVE-2026-14440 [-] References: https://notcve.org/notcve/NotCVE-2026-0001 (full technical record, preserved since day one) https://notcve.org/cve/CVE-2026-14440 [-] About NotCVE: NotCVE (https://notcve.org assigns public, timestamped NotCVE IDs to vulnerabilities not acknowledged by vendors. Vendor will not assign a CVE? Request a NotCVE: https://notcve.org/form/ · Contributors: https://notcve.org/hall/ _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- [NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure NotCVE Advisories (Jul 15)
Facts Only
* NotCVE-2026-0001 was published on 2026-01-19 with no CVE assigned.
* Cloudflare assigned CVE-2026-14440 to the same issue on 2026-07-01.
* The vulnerability affects Cloudflare Universal SSL (managed CAA record augmentation).
* The affected behavior occurs at the service-side; no customer-side patch is applicable.
* Cloudflare adds CAA issue/issuewild records when Universal SSL is enabled and CAA records are published for the zone.
* These auto-added records appear in DNS responses but not in the Cloudflare dashboard.
* The issue relates to how auto-added CAA properties interact with RFC 8657 constraints on account binding.
* The vulnerability may enable unauthorized DV certificate issuance by weakening intended account binding.
Executive Summary
Full Take
Sentinel — Human
This text functions as a factual timeline and technical description of a vulnerability disclosure, exhibiting the precision expected from an advisory rather than general narrative reporting.
