Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89178.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-89178
Upstream
  • CVE-2026-42013
Published
2026-05-26T22:16:42Z
Modified
2026-08-28T17:48:10Z
Summary
CVE-2026-42013 affecting package gnutls for versions less than 3.8.13-1
Details

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.

References

Affected packages

Azure Linux:3 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/azure-linux/gnutls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.8.13-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89178.json"