CVE-2025-14831
published 2026-02-09CVE-2025-14831: A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.64%
46.5th percentile
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.7.9-2+deb12u6 (bookworm) | gnutls28 3.7.9-2+deb12u6 (bookworm) |
| ubuntu | gnutls28 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gnutls28 vulnerabilities
osv·2026-02-16·CVSS 5.3
CVE-2025-14831 [MEDIUM] gnutls28 vulnerabilities
gnutls28 vulnerabilities
Tim Scheckenbach discovered that GnuTLS incorrectly handled malicious
certificates containing a large number of name constraints and subject
alternative names. A remote attacker could possibly use this issue to
cause GnuTLS to consume resources, resulting in a denial of service.
(CVE-2025-14831)
Luigino Camastra discovered that GnuTLS incorrectly handled certain PKCS11
token labels. A remote attacker could use this issue to cause GnuTLS to
crash, resulting in a denial of service, or possibly execute arbitrary
code. The default compiler options for affected releases should reduce the
vulnerability to a denial of service. (CVE-2025-9820)
OSV
CVE-2025-14831: A flaw was found in GnuTLS
osv·2026-02-09·CVSS 5.3
CVE-2025-14831 [MEDIUM] CVE-2025-14831: A flaw was found in GnuTLS
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
GHSA
GHSA-pm8w-jq9r-x5rp: A flaw was found in GnuTLS
ghsa_unreviewed·2026-02-09
CVE-2025-14831 [MEDIUM] CWE-407 GHSA-pm8w-jq9r-x5rp: A flaw was found in GnuTLS
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 7.5
CVE-2026-33846 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker
could possibly use this issue to recover sensitive information. This
issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this
issue to cause GnuTLS to consume resources, leading to a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)
Luigino Camastra discovered that GnuTLS incorrectly handled certain
PKCS11 token labels. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a deni
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-02-16·CVSS 5.3
CVE-2025-14831 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Tim Scheckenbach discovered that GnuTLS incorrectly handled malicious
certificates containing a large number of name constraints and subject
alternative names. A remote attacker could possibly use this issue to
cause GnuTLS to consume resources, resulting in a denial of service.
(CVE-2025-14831)
Luigino Camastra discovered that GnuTLS incorrectly handled certain PKCS11
token labels. A remote attacker could use this issue to cause GnuTLS to
crash, resulting in a denial of service, or possibly execute arbitrary
code. The default compiler options for affected releases should reduce the
vulnerability to a denial of service. (CVE-2025-9820)
Instructions: In general, a standard system update will make all th
Red Hat
gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
vendor_redhat·2026-02-09·CVSS 5.3
CVE-2025-14831 [MEDIUM] CWE-407 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Statement: This vulnerability is rated Moderate for Red Hat. GnuTLS is susceptible to a denial of service attack due to excessive CPU and memory c
Debian
CVE-2025-14831: gnutls28 - A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) ...
vendor_debian·2025·CVSS 5.3
CVE-2025-14831 [MEDIUM] CVE-2025-14831: gnutls28 - A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) ...
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Scope: local
bookworm: resolved (fixed in 3.7.9-2+deb12u6)
bullseye: resolved (fixed in 3.7.1-5+deb11u9)
forky: resolved (fixed in 3.8.12-1)
sid: resolved (fixed in 3.8.12-1)
trixie: resolved (fixed in 3.8.9-3+deb13u2)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14831 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-14831 [HIGH] CVE-2025-14831 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14831 :
GnuTLS vulnerability analysis and mitigation
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Source : NVD
## 5.3
Score
Published February 9, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
GnuTLS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libgnutls30-32bit
gnutls-guile
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Mar 29, 2026
Wiz
CVE-2025-9820 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2025-9820 [MEDIUM] CVE-2025-9820 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-9820 :
GnuTLS vulnerability analysis and mitigation
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.
Source : NVD
## 4
Score
Published January 26, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
GnuTLS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA
Wiz
CVE-2026-1584 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-1584 [HIGH] CVE-2026-1584 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1584 :
GnuTLS vulnerability analysis and mitigation
A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server.
Source : NVD
Published February 10, 2026
CNA Score N/A
Affected Technologies
GnuTLS
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
gnutls-c++-debuginfo
gnutls-dane-debuginfo
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Has Fix Added at: Feb 24, 2026
Alpine edge Has Fix Added at: Feb 11, 2026
Debian 14 Has Fix Added at: Feb 10, 2026
Debian Has Fix Added at: Feb 11, 2026
## Get a CVE risk assess
Bugzilla
CVE-2025-14831 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
bugzilla·2025-12-17·CVSS 5.3
CVE-2025-14831 [MEDIUM] CVE-2025-14831 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
CVE-2025-14831 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
Verifying Certificates with large amout of name constraints and subject alternative names makes GnuTLS vulnerable to DoS attacks
When trying to verify a certificate chain using the certtool --verify command, with certificates, that contain a larger number of SANs and Name Constraints, GnuTLS tries to verify all of them, without any bound on the quantity of those fields.
Using those crafted malicious certificate, GnuTLS is vulnerable to DoS attacks by excessive usage of CPU and memory.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:3477 https://access.redhat.com/errata/RHSA-2026:3477
---
This issue has bee
https://access.redhat.com/errata/RHSA-2026:13812https://access.redhat.com/errata/RHSA-2026:16008https://access.redhat.com/errata/RHSA-2026:16009https://access.redhat.com/errata/RHSA-2026:16174https://access.redhat.com/errata/RHSA-2026:25096https://access.redhat.com/errata/RHSA-2026:30849https://access.redhat.com/errata/RHSA-2026:30850https://access.redhat.com/errata/RHSA-2026:33125https://access.redhat.com/errata/RHSA-2026:3477https://access.redhat.com/errata/RHSA-2026:4188https://access.redhat.com/errata/RHSA-2026:4655https://access.redhat.com/errata/RHSA-2026:4943https://access.redhat.com/errata/RHSA-2026:5585https://access.redhat.com/errata/RHSA-2026:5606https://access.redhat.com/errata/RHSA-2026:6618https://access.redhat.com/errata/RHSA-2026:6630https://access.redhat.com/errata/RHSA-2026:6737https://access.redhat.com/errata/RHSA-2026:6738https://access.redhat.com/errata/RHSA-2026:7329https://access.redhat.com/errata/RHSA-2026:7335https://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/errata/RHSA-2026:8746https://access.redhat.com/errata/RHSA-2026:8747https://access.redhat.com/errata/RHSA-2026:8748https://access.redhat.com/security/cve/CVE-2025-14831https://bugzilla.redhat.com/show_bug.cgi?id=2423177https://gitlab.com/gnutls/gnutls/-/issues/1773https://cert-portal.siemens.com/productcert/html/ssa-032379.html
2026-02-09
Published