Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
Fixed in: GnuTLS 3.8.13
patched
details
Finding IDs
F-GNUTLS-HOSTNAME-001
CVE
CVE-2026-42012
Status
patched
Fixed in
GnuTLS 3.8.13
Recorded credit
reported by Oleh Konko (1seal)
Note
x509/hostname-verify: make URI/SRV SAN preclude CN fallback
CVE registry state
PUBLISHED
CVE state checked
F-GNUTLS-HOSTNAME-001: Verification failures. URI or SRV SAN entries incorrectly permit common-name fallback. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.