GnuTLS | gnutls_certificate_verify_peers2() does not seem to verify ExtendedKeyUsage (#1886)
Read-only notification of GnuTLS library development activities <[email protected]> Fri, 15 May 2026 21:43:26 +0000
| Newsgroups | gmane.comp.encryption.gpg.gnutls.devel |
|---|---|
| Message-ID | <[email protected]> |
Daniel Stenberg created an issue: https://gitlab.com/gnutls/gnutls/-/work_items/1886 gnutls_certificate_verify_peers2() does not seem to verify ExtendedKeyUsage but gnutls_certificate_verify_peers() does. Neither case is documented clearly. This has already lead to people submitting vuln reports to gnutls-using apps for this omission. Reference: https://www.tenable.com/security/research/tra-2026-38 The aria2c fix: https://github.com/aria2/aria2/pull/2356/changes This seems like a GnuTLS bug to me. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1886 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/sent_notifications/4-al508pkdqcnun9ilftsla8p1g-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help _______________________________________________ Gnutls-devel mailing list [email protected] http://lists.gnupg.org/mailman/listinfo/gnutls-devel