CVE-2020-15104
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-15104 is a TLS certificate validation vulnerability discovered in Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0. The vulnerability involves incorrect validation of wildcard DNS Subject Alternative Names (SANs) in TLS certificates, where Envoy would improperly allow a wildcard certificate to apply to multiple subdomain levels (GitHub Advisory).

Technical details

The vulnerability stems from Envoy's TLS certificate validation logic incorrectly allowing a wildcard DNS Subject Alternative Name to apply to multiple subdomain levels. For example, a certificate with a SAN of *.example.com would incorrectly be allowed to validate against nested.subdomain.example.com, when it should only validate against single-level subdomains like subdomain.example.com. This affects both client certificate validation in mTLS and server certificate validation for upstream connections. The vulnerability has been assigned a CVSS v3.1 base score of 5.4 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N (NVD).

Impact

The vulnerability impacts configurations that use verify_subject_alt_name in any Envoy version, or match_subject_alt_names in version 1.14 or later. It is particularly concerning in situations where an untrusted entity can obtain a signed wildcard TLS certificate for a domain of which only a subdomain is intended to be trusted. For example, if an application intends to trust api.mysubdomain.example.com, an attacker with a valid certificate for *.example.com could potentially exploit this vulnerability (GitHub Advisory).

Exploitability

The vulnerability is exploitable in scenarios where an attacker can obtain a signed wildcard TLS certificate for a parent domain when only a specific subdomain should be trusted. The attack requires the ability to obtain valid signed certificates for the target domains (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Envoy versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0. Users are advised to upgrade to these patched versions or later. No workarounds are available for unpatched versions (GitHub Advisory, Red Hat).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management