CVE-2026-42012
7.1 HIGHA flaw was found in gnutls
Published: 2026-05-26 · Last updated: 2026-06-02
Severity and scoring
- CVSS
- 7.1 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
- CWE
- CWE-295
Description
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-42012
- [Other]https://access.redhat.com/errata/RHSA-2026:20611
- [Other]https://access.redhat.com/errata/RHSA-2026:20612
- [Other]https://access.redhat.com/errata/RHSA-2026:20613
- [Other]https://access.redhat.com/security/cve/CVE-2026-42012
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=2467441
Related CVEs
Same CWE
- CVE-2025-71261 — An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere... (8.6 HIGH)
- CVE-2026-9259 — Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier (6.5 MEDIUM)
- CVE-2026-9258 — Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier (6.5 MEDIUM)
- CVE-2026-45388 — In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows imp... (9.1 CRITICAL)
- CVE-2026-45170 — Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validati...