{"id":"CVE-2026-88648","title":"Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.","summary":"Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.","severity":"none","published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:33:42.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88648","references":[{"url":"https://gist.github.com/lkloliver/1f2a97cb8d0b31aa27b6bd0354358d7d","label":"cve@mitre.org"},{"url":"https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10","label":"cve@mitre.org"},{"url":"https://www.rfc-editor.org/rfc/rfc5280#section-6.1.4","label":"cve@mitre.org"}],"tags":["nvd"],"ingestedAt":"2026-10-08T20:06:22.191Z","slug":"CVE-2026-88648","body":"## Overview\n\nIncomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}