Back

HIGH

Gnutls: gnutls: security bypass due to incorrect name constraint handling

Published May 7, 2026

Description

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 7, 2026
Updated Oct 2, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated May 7, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity Moderate
Public date Apr 29, 2026