---
id: CVE-2026-42013
title: A flaw was found in gnutls
summary: >-
  A flaw was found in gnutls. When validating certificates, an oversized Subject
  Alternative Name (SAN) could cause the validation process to incorrectly fall
  back to checking the Common Name (CN) field. This could allow a remote
  attacker …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-295
published: '2026-05-26'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42013'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:20611'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:20612'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:20613'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:26319'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:26409'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:29197'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30004'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30849'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30850'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:32962'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42013'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2467448'
    label: secalert@redhat.com
  - url: 'https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00423
epssPercentile: 0.36229
ingestedAt: '2026-06-29T13:42:11.959Z'
---

## Overview

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
