CVE-2026-3833
published 2026-04-30CVE-2026-3833: A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for…
PriorityP348high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.57%
43.2th percentile
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| ubuntu | gnutls28 | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_ubuntu9.1CRITICAL
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6rgh-57xm-37v8: A flaw was found in gnutls
ghsa_unreviewed·2026-04-30
CVE-2026-3833 [MEDIUM] CWE-178 GHSA-6rgh-57xm-37v8: A flaw was found in gnutls
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
VulDB
GnuTLS Certificate dNSName/rfc822Name case sensitivity
vuldb·2026-04-30·CVSS 6.5
CVE-2026-3833 [MEDIUM] GnuTLS Certificate dNSName/rfc822Name case sensitivity
A vulnerability has been found in GnuTLS and classified as critical. This affects an unknown function of the component Certificate Handler. The manipulation of the argument dNSName/rfc822Name leads to improper handling of case sensitivity.
This vulnerability is referenced as CVE-2026-3833. Remote exploitation of the attack is possible. No exploit is available.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 7.5
CVE-2026-33846 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker
could possibly use this issue to recover sensitive information. This
issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this
issue to cause GnuTLS to consume resources, leading to a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)
Luigino Camastra discovered that GnuTLS incorrectly handled certain
PKCS11 token labels. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a deni
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-05-20·CVSS 9.1
CVE-2026-42015 [CRITICAL] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Joshua Rogers discovered that GnuTLS did not properly handle malformed
DTLS handshake fragments in certain cases. A remote attacker could
possibly use this issue to obtain sensitive information, or cause a
denial of service. (CVE-2026-33845)
Haruto Kimura, Oscar Reparaz, and Zou Dikai discovered that GnuTLS did
not properly validate DTLS handshake fragment lengths in certain cases. A
remote attacker could possibly use this issue to cause GnuTLS to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2026-33846)
Oleh Konko and Joshua Rogers discovered that GnuTLS did not properly
validate OCSP responses in certain cases. A remote attacker could
possibly use this issue to bypass certi
Red Hat
gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
vendor_redhat·2026-04-30·CVSS 6.5
CVE-2026-3833 [MEDIUM] CWE-178 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
Statement: This issue is particularly important because it affects the correct enforcement of X.509 nameConstraints, which are specifically designed to limit the authority of su
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison [fedora-all]
bugzilla·2026-05-14·CVSS 6.5
CVE-2026-3833 [MEDIUM] CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison [fedora-all]
CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
bugzilla·2026-03-09·CVSS 6.5
CVE-2026-3833 [MEDIUM] CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
gnutls compares nameConstraints labels using a case-sensitive memcmp path without an ascii-casefold canonicalization step. when excludedSubtrees/permittedSubtrees dNSName (dns) or rfc822Name (email) constraints are present, attacker-controlled casing differences in the leaf certificate SAN can cause a false accept (policy bypass) where the certificate should be rejected.
https://access.redhat.com/errata/RHSA-2026:13274https://access.redhat.com/errata/RHSA-2026:20611https://access.redhat.com/errata/RHSA-2026:20612https://access.redhat.com/errata/RHSA-2026:20613https://access.redhat.com/errata/RHSA-2026:26319https://access.redhat.com/errata/RHSA-2026:26409https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:30004https://access.redhat.com/errata/RHSA-2026:30849https://access.redhat.com/errata/RHSA-2026:30850https://access.redhat.com/errata/RHSA-2026:32962https://access.redhat.com/errata/RHSA-2026:33125https://access.redhat.com/security/cve/CVE-2026-3833https://bugzilla.redhat.com/show_bug.cgi?id=2445763https://gitlab.com/gnutls/gnutls/-/issues/1803https://gitlab.com/gnutls/gnutls/-/issues/1803
2026-04-30
Published