Executive brief
GnuTLS is a widely used security library that helps applications establish secure encrypted connections. A flaw was found where the library incorrectly validates digital certificates due to how it handles uppercase and lowercase letters in domain names and email addresses. An attacker could use a specially crafted certificate to bypass security policies, potentially leading to unauthorized access to sensitive data or systems.
Technical details
A vulnerability exists in GnuTLS due to improper handling of case sensitivity (CWE-178) during X.509 certificate validation. The library performs case-sensitive comparisons using memcmp for nameConstraints labels, specifically for dNSName and rfc822Name constraints within excludedSubtrees or permittedSubtrees, without an ASCII case-folding step. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN) that differ from the defined constraints. This results in a policy bypass where a certificate that should be rejected is accepted. Patches have been released by Red Hat and GnuTLS upstream to address this issue.
Affected products
- GNU GnuTLS 3.8.13-1, 3.6.16-8.el8_10.6
- Red Hat Enterprise Linux 6.0, 7.0, 8.0, 9.0, 10.0
- Red Hat Openshift Container Platform 4.0
Timeline
- 2026-03-09: disclosed: Initial report in Red Hat Bugzilla
- 2026-04-30: advisory: NVD and Red Hat published initial CVE details
- 2026-05-02: patched: Red Hat released security advisory RHSA-2026:13274