LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-42012

Published
CVSS7.1
Severityhigh
WeaknessCWE-295
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

Description

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-42012

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-42012.