CVE-2026-88648: GNUTLS GNUTLS vulnerability
Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must control a subordinate Certificate Authority. The issue is relevant where that subordinate CA is constrained to particular domains but its certificates are trusted by relying parties using the affected GnuTLS implementation.
What security boundary can be bypassed?
The vulnerability can bypass cross-domain PKI restrictions, allowing a controlled subordinate CA to issue unauthorized certificates outside the domains it is intended to serve.
How can I determine whether an environment may be affected?
Review systems using GnuTLS v3.8.13 and identify trust chains that include subordinate CAs with domain-related certificate constraints. Those systems may be affected if they rely on GnuTLS to enforce those constraints during X.509 certificate validation.