[gnutls-devel] GnuTLS | [HIGH] gnutls x509 nameconstraints: excluded dns/email subtree bypass via case-sensitive comparison (security report) (#1803)

Read-only notification of GnuTLS library development activities gnutls-devel at lists.gnutls.org
Thu Apr 30 13:00:41 CEST 2026




Alexander Sosedkin commented: https://gitlab.com/gnutls/gnutls/-/issues/1803#note_3303260975


I'd like to apologize for the confusion about the severity of this one,
I guess I've forgot to act on the discussion above and claimed the severity to be High in NEWS and on the website.

I'll change it to Moderate on the website
(https://gitlab.com/gnutls/web-pages/-/commit/995d4e7da329f1efbb5d59735fc8a0fd5dab40a1),
and will send a follow-up to the announcement email clarifying the severity.

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/issues/1803#note_3303260975
You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/sent_notifications/4-2nmn7e2zs2cewqqysd6iaz8ph-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-devel/attachments/20260430/881235aa/attachment.html>


More information about the Gnutls-devel mailing list