Name Constraint Bypass in GnuTLS Allows Spoofing in Certificate Validation
CVE-2026-42011
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 7 May 2026
What is CVE-2026-42011?
A critical flaw in the GnuTLS library allows attackers to bypass name constraints during certificate validation. The vulnerability stems from the incorrect handling of permitted name constraints when excluded name constraints are present from previous Certificate Authorities (CAs). By exploiting this weakness, an attacker could present invalid certificates, leading to risks such as spoofing and man-in-the-middle attacks on affected systems. It is crucial for affected users and organizations to update GnuTLS to secure their applications and maintain the integrity of their certificate validation processes.
Affected Version(s)
Red Hat Enterprise Linux 8 0:3.6.16-8.el8_10.6
Red Hat Enterprise Linux 8 0:3.6.16-8.el8_10.6
Red Hat Hardened Images 3.8.13-1.hum1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved