Description
A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.
Published: 2026-10-08
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Man‑in‑the‑Middle (eavesdropping)
Action: Patch
AI Analysis

Impact

A hostname verification bypass in GnuTLS v3.8.13 allows an attacker to trick the client into accepting a certificate that does not properly match the target host. By exploiting the Common Name fallback mechanism the attacker can gain access to encrypted traffic, effectively turning secure TLS sessions into readable data streams. This compromise undermines confidentiality and can be used for stealthy data exfiltration or tampering.

Affected Systems

The vulnerability affects GnuTLS version 3.8.13. No other vendors or products are explicitly listed, and affected builds appear to be those including the hostname verification logic in that release.

Risk and Exploitability

The CVSS score is not supplied, but the ability to bypass hostname checks suggests a high severity. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, so the exact exploitation likelihood is unclear. The attack surface requires that the victim use GnuTLS 3.8.13 and that the attacker can present a crafted certificate; however, the lack of a mandatory certificate chain check makes the exploitation in the wild plausible.

Generated by OpenCVE AI on October 8, 2026 at 18:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to GnuTLS 3.8.14 or later where the hostname verification bug is fixed
  • Configure applications to reject certificates whose Common Name does not match the server hostname, thereby disabling the vulnerable fallback logic
  • Monitor TLS connections for anomalous certificates or unexpected traffic that may indicate exploitation

Generated by OpenCVE AI on October 8, 2026 at 18:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title GnuTLS 3.8.13 Hostname Verification Bypass Enables Eavesdropping gnutls: gnutls: Information disclosure via hostname verification bypass
Weaknesses CWE-295
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Important


Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Title GnuTLS 3.8.13 Hostname Verification Bypass Enables Eavesdropping
Weaknesses CWE-640

Thu, 08 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-08T16:35:41.361Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88647

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T17:17:17.783

Modified: 2026-10-08T21:33:42.423

Link: CVE-2026-88647

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-08T00:00:00Z

Links: CVE-2026-88647 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password