CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being
case-sensitive (bsc#1263707).
CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange
(bsc#1263715).
CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation
(bsc#1263710).
CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712).
CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks
a protected authentication path (bsc#1263713).
CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714).