CVE-2026-42013
HIGHCVSS 8.2/10EPSS 0.39%
Last modified
This CVE is reserved or awaiting analysis. Details will appear once published by NVD.
Description
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Are you affected by CVE-2026-42013?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
