GnuTLS | gnutls_certificate_verify_peers2() does not seem to verify ExtendedKeyUsage (#1886)

Read-only notification of GnuTLS library development activities <[email protected]> Fri, 15 May 2026 21:43:26 +0000
Newsgroups gmane.comp.encryption.gpg.gnutls.devel
Message-ID <[email protected]>

Daniel Stenberg created an issue: https://gitlab.com/gnutls/gnutls/-/work_items/1886



gnutls_certificate_verify_peers2() does not seem to verify ExtendedKeyUsage but gnutls_certificate_verify_peers() does.

Neither case is documented clearly. This has already lead to people submitting vuln reports to gnutls-using apps for this omission.

Reference: https://www.tenable.com/security/research/tra-2026-38

The aria2c fix: https://github.com/aria2/aria2/pull/2356/changes

This seems like a GnuTLS bug to me.

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1886
You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/sent_notifications/4-al508pkdqcnun9ilftsla8p1g-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help

_______________________________________________
Gnutls-devel mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnutls-devel