And for anyone who doesn't get why this should not be allowed.
Think about wildcards and how they work for a second.
Now apply that to any TLD... like DOT COM:
Should anyone ever trust a CA issued cert with the SAN entry *.com ?
CA CERT TYPE DOMAIN (CN) KEY ALG VALID FROM VALID TO EXPIRES IN SANs
R3 Final cert riyadh.ye RSA 2048bit 2021-Feb-03 05:50 UTC 2021-May-04 05:50 UTC 89 days *.riyadh.ye
riyadh.ye