CVE-2026-42011: Red Hat Cert Manager Support For Red Hat Openshift Release 1.20

High severity, CVSS 7.4. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.

Affected products

  • Red Hat Cert Manager Support For Red Hat Openshift Release 1.20: before 1790598593 (fixed in 1790598593)
  • Red Hat Red Hat Discovery 2: before 1782159791 (fixed in 1782159791); before 1782166952 (fixed in 1782166952)
  • Red Hat Red Hat Enterprise Linux 10: before 0:3.8.10-4.el10_2 (fixed in 0:3.8.10-4.el10_2)
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.8.9-9.el10_0.19 (fixed in 0:3.8.9-9.el10_0.19)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:3.3.29-9.el7_9.2 (fixed in 0:3.3.29-9.el7_9.2)
  • Red Hat Red Hat Enterprise Linux 8: before 0:3.6.16-8.el8_10.6 (fixed in 0:3.6.16-8.el8_10.6)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:3.6.14-10.el8_4.1 (fixed in 0:3.6.14-10.el8_4.1); before 0:4.13-3.el8_4.1 (fixed in 0:4.13-3.el8_4.1)
  • Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:3.6.14-10.el8_4.1 (fixed in 0:3.6.14-10.el8_4.1); before 0:4.13-3.el8_4.1 (fixed in 0:4.13-3.el8_4.1)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:3.6.16-5.el8_6.5 (fixed in 0:3.6.16-5.el8_6.5); before 0:4.13-3.el8_6.2 (fixed in 0:4.13-3.el8_6.2)
  • Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:3.6.16-5.el8_6.5 (fixed in 0:3.6.16-5.el8_6.5); before 0:4.13-3.el8_6.2 (fixed in 0:4.13-3.el8_6.2)
  • Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:3.6.16-7.el8_8.4 (fixed in 0:3.6.16-7.el8_8.4); before 0:4.13-4.el8_8.1 (fixed in 0:4.13-4.el8_8.1)
  • Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:3.6.16-7.el8_8.4 (fixed in 0:3.6.16-7.el8_8.4); before 0:4.13-4.el8_8.1 (fixed in 0:4.13-4.el8_8.1)
  • Red Hat Red Hat Enterprise Linux 9: before 0:3.8.10-4.el9_8 (fixed in 0:3.8.10-4.el9_8)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:3.7.6-21.el9_2.7 (fixed in 0:3.7.6-21.el9_2.7)
  • Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:3.8.3-4.el9_4.6 (fixed in 0:3.8.3-4.el9_4.6)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:3.8.3-6.el9_6.4 (fixed in 0:3.8.3-6.el9_6.4)
  • Red Hat Red Hat Hardened Images: before 3.8.13-1.hum1 (fixed in 3.8.13-1.hum1)
  • Red Hat Red Hat Openshift Ai 3.4: before 1790703542 (fixed in 1790703542)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Container Platform 4.12: before 412.86.202608241157-0 (fixed in 412.86.202608241157-0)
  • Red Hat Red Hat Openshift Container Platform 4.16: before 416.94.202608150307-0 (fixed in 416.94.202608150307-0)
  • Red Hat Red Hat Openshift Container Platform 4.17: before 417.94.202608250221-0 (fixed in 417.94.202608250221-0)
  • Red Hat Red Hat Openshift Container Platform 4.18: before 418.94.202608142238-0 (fixed in 418.94.202608142238-0)
  • Red Hat Red Hat Openshift Container Platform 4.19: before 4.19.9.6.202607151909-0 (fixed in 4.19.9.6.202607151909-0)
  • and 1 more

Published 2026-05-07. Last modified 2026-10-10.