---
id: CVE-2026-42012
title: A flaw was found in gnutls
summary: >-
  A flaw was found in gnutls. A remote attacker could exploit this vulnerability
  by presenting a specially crafted certificate that contains Uniform Resource
  Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could
  ca…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'
cwe:
  - CWE-295
published: '2026-05-26'
updated: '2026-06-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42012'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:20611'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:20612'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:20613'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:26319'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:26409'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:29197'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30004'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42012'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2467441'
    label: secalert@redhat.com
  - url: 'https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00354
epssPercentile: 0.29009
ingestedAt: '2026-06-26T16:43:14.185Z'
---

## Overview

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
