CVE-2026-42013

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Se descubrió un fallo en gnutls. Al validar certificados, un Subject Alternative Name (SAN) de tamaño excesivo podría hacer que el proceso de validación recurriera incorrectamente a la comprobación del campo Common Name (CN). Esto podría permitir a un atacante remoto eludir la validación correcta del certificado, lo que podría conducir a ataques de suplantación de identidad o man-in-the-middle.

22 Jul 2026, 16:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:40762 -
  • () https://access.redhat.com/errata/RHSA-2026:43575 -

20 Jul 2026, 12:19

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:41921 -

15 Jul 2026, 15:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:13274 -

30 Jun 2026, 03:19

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:33125 -

29 Jun 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:32962 -

29 Jun 2026, 09:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:30849 -
  • () https://access.redhat.com/errata/RHSA-2026:30850 -

26 Jun 2026, 08:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:30004 -

26 Jun 2026, 00:16

Type Values Removed Values Added
References
  • () https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8 -
CWE CWE-1284 CWE-295

24 Jun 2026, 17:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:29197 -

17 Jun 2026, 13:20

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:26319 -
  • () https://access.redhat.com/errata/RHSA-2026:26409 -

02 Jun 2026, 16:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:20612 -

01 Jun 2026, 21:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:20613 -

27 May 2026, 04:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:20611 -

26 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 22:16

Updated : 2026-07-24 11:10


NVD link : CVE-2026-42013

Mitre link : CVE-2026-42013

CVE.ORG link : CVE-2026-42013


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation