GNUTLS Name Constraint Bypass (CVE-2026-42011)
CVE-2026-42011 Published on May 7, 2026
Gnutls: gnutls: security bypass due to incorrect name constraint handling
A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.
Vulnerability Analysis
CVE-2026-42011 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-42011
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42011 are published in these products:
Affected Versions
Red Hat Enterprise Linux 10:- Version 0:3.8.10-4.el10_2 and below * is unaffected.
- Version 0:3.6.16-8.el8_10.6 and below * is unaffected.
- Version 0:3.6.16-8.el8_10.6 and below * is unaffected.
- Version 0:3.8.10-4.el9_8 and below * is unaffected.
- Version 0:3.8.10-4.el9_8 and below * is unaffected.
- Version 3.8.13-1.hum1 and below * is unaffected.