{"id":"CVE-2026-88647","title":"A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.","summary":"A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.","severity":"none","published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:33:42.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88647","references":[{"url":"https://gist.github.com/lkloliver/f98ec3de1a871fdfc02b70b8b9ba7642","label":"cve@mitre.org"},{"url":"https://gitlab.com/gnutls/gnutls/-/issues/1802","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T16:52:14.786Z","slug":"CVE-2026-88647","body":"## Overview\n\nA hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}