Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-13645

24
FAUCET Score

CVE-2020-13645 describes a vulnerability in GNOME glib-networking (through version 2.64.2) where GTlsClientConnection fails to perform hostname verification on TLS certificates if the application does not explicitly provide the server identity, contrary to its intended design. This medium-severity vulnerability (CVSS 6.5) allows an attacker to present a valid certificate for any host, potentially leading to information disclosure or integrity compromise (CWE-295). While affecting products from Broadcom, Canonical, Fedora, GNOME, and NetApp, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.5.11CPE matchmatch criteria
cpe:2.3:a:gnome:balsa:*:*:*:*:*:*:*:*
2.6.0CPE matchmatch criteria
cpe:2.3:a:gnome:balsa:2.6.0:*:*:*:*:*:*:*
< 2.62.4CPE matchmatch criteria
cpe:2.3:a:gnome:glib-networking:*:*:*:*:*:*:*:*
>= 2.64.0, < 2.64.3CPE matchmatch criteria
cpe:2.3:a:gnome:glib-networking:*:*:*:*:*:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.93%
Probability of exploitation in next 30 days
EPSS Percentile
77.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0193 is in the 66th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: cbl2 glib-networking 2.59.1-8 on CBL Mariner 2.0Fixed in: 2.59.1-8
microsoftpatch availablevia msrc
Product: 19180-16823Fixed in: 2.59.1-8
microsoftpatch availablevia msrc
Product: cm1 glib-networking 2.59.1-6 on CBL Mariner 1.0Fixed in: 2.59.1-6
microsoftpatch availablevia msrc
Product: 19179-16820Fixed in: 2.59.1-6
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 2.59.1-6
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 2.59.1-6
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.59.1-8
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.59.1-8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: glib-networking
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: glib-networking

Vendor Advisories (3)

microsoft2020-Aug/CVE-2020-13645

CVE-2020-13645

Aug 11, 2020
microsoft2020-May/CVE-2020-13645Moderate

In GNOME glib-networking through 2.64.2 the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior to fail the certificate verification. Applications that fail to provide the server identity including Balsa before 2.5.11 and 2.6.x before 2.6.1 accept a TLS certificate if the certificate is valid for any host.

May 12, 2020
redhatCVE-2020-13645Moderate

glib-networking: GTlsClientConnection silently ignores unset server identity

May 4, 2020

References

gitlab.gnome.org / GNOME/balsa/-/issues/34
ExploitVendor Advisory
gitlab.gnome.org / GNOME/glib-networking/-/issues/135
ExploitVendor Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HLEX2IP62SU6WJ4SK3U766XGLQK3J62O
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/LRCUM22YEWWKNMN2BP5LTVDM5P4VWIXS
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TQEQJQ4XFMFCFJTEXKL2ZO3UELBPCKSK
security.gentoo.org / glsa/202007-50
Third Party Advisory
security.netapp.com / advisory/ntap-20200608-0004
Third Party Advisory
usn.ubuntu.com / 4405-1
Third Party Advisory