Description
Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
Published: 2026-10-08
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Patch Immediately
AI Analysis

Impact

GnuTLS version 3.8.13 contains a flaw that causes the library to accept certificates whose extensions do not comply with RFC standards. This weakness (CWE-295) allows an untrusted or compromised certificate to be treated as valid, effectively bypassing the intended authentication checks. This weakness does not allow arbitrary code execution but permits an attacker to masquerade as a legitimate server or client, enabling impersonation or man‑in‑the‑middle scenarios.

Affected Systems

All installations that use GnuTLS 3.8.13 as part of their TLS stack are susceptible. This includes any software that links with that library for either client or server functionality, regardless of the programming language or platform.

Risk and Exploitability

The CVSS score is 9.1, and the EPSS score is not available. Based on the description, it is inferred that an attacker who can supply a forged certificate during the TLS handshake has a high likelihood of success. The likely attack vector is remote, requiring only the ability to influence the certificate presented in the handshake. While the vulnerability is not listed in the CISA KEV catalog, the potential for impersonation or man‑in‑the‑middle attacks remains high.

Generated by OpenCVE AI on October 8, 2026 at 21:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GnuTLS to version 3.8.14 or later, which includes the fixed certificate validation logic.
  • If an upgrade is not immediately possible, reconfigure affected applications or the library to enforce strict certificate validation and disallow certificates with disallowed extensions, if supported.
  • Monitor TLS connections for anomalous certificates and review logs for unexpected certificate chains during the transition period.

Generated by OpenCVE AI on October 8, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
Title GnuTLS 3.8.13 improper certificate validation permits acceptance of certificates with invalid extensions

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Title GnuTLS 3.8.13 improper certificate validation permits acceptance of certificates with invalid extensions

Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Thu, 08 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Description Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-08T18:28:52.324Z

Reserved: 2026-09-22T00:00:00.000Z

Link: CVE-2026-95210

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T18:18:33.370

Modified: 2026-10-08T21:33:42.423

Link: CVE-2026-95210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T22:00:19Z

Weaknesses
  • CWE-295

    Improper Certificate Validation