Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89187.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-89187
Upstream
  • CVE-2026-42012
Published
2026-05-26T22:16:41Z
Modified
2026-08-28T17:48:10Z
Summary
CVE-2026-42012 affecting package gnutls for versions less than 3.8.13-1
Details

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.

References

Affected packages

Azure Linux:3 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/azure-linux/gnutls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.8.13-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89187.json"