Back

HIGH

Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans

Published May 26, 2026

Description

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 26, 2026
Updated Oct 2, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated May 27, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity Moderate
Public date Apr 29, 2026