Project Subscriptions
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4595-1 | gnutls28 security update |
Debian DSA |
DSA-6281-1 | gnutls28 security update |
Ubuntu USN |
USN-8284-1 | GnuTLS vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu gnutls Redhat hardened Images Redhat openshift Container Platform |
|
| Vendors & Products |
Gnu
Gnu gnutls Redhat hardened Images Redhat openshift Container Platform |
Wed, 27 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:8::appstream cpe:/o:redhat:enterprise_linux:8::baseos |
|
| References |
|
Tue, 26 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information. | |
| Title | Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-27T14:21:54.475Z
Reserved: 2026-04-23T11:23:46.517Z
Link: CVE-2026-42012
Updated: 2026-05-27T14:21:50.991Z
Status : Awaiting Analysis
Published: 2026-05-26T22:16:41.913
Modified: 2026-05-27T14:54:20.160
Link: CVE-2026-42012
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:08:16Z
Debian DLA
Debian DSA
Ubuntu USN