CVE-2026-42013

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-26 22:16

Updated : 2026-09-03 15:17


NVD link : CVE-2026-42013

Mitre link : CVE-2026-42013

CVE.ORG link : CVE-2026-42013


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation