A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | GnuTLS 3.8.13 Hostname Verification Bypass Enables Eavesdropping | |
| Weaknesses | CWE-640 |
Thu, 08 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-08T16:35:41.361Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88647
No data.
Status : Received
Published: 2026-10-08T17:17:17.783
Modified: 2026-10-08T17:17:17.783
Link: CVE-2026-88647
No data.
OpenCVE Enrichment
Updated: 2026-10-08T19:00:07Z
Weaknesses