Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3rqj-4qqw-jgwr

Опубликовано: 30 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

EPSS

Процентиль: 53%
0.00739
Низкий

3.7 Low

CVSS3

Дефекты

CWE-179

Связанные уязвимости

CVSS3: 3.7
ubuntu
5 месяцев назад

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

CVSS3: 3.7
redhat
5 месяцев назад

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

CVSS3: 3.7
nvd
5 месяцев назад

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

CVSS3: 3.7
msrc
4 месяца назад

Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response

CVSS3: 3.7
debian
5 месяцев назад

A flaw was found in gnutls. A remote attacker could exploit this vulne ...

EPSS

Процентиль: 53%
0.00739
Низкий

3.7 Low

CVSS3

Дефекты

CWE-179