Количество 20
Количество 20
CVE-2026-3833
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
CVE-2026-3833
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
CVE-2026-3833
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
CVE-2026-3833
Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
CVE-2026-3833
A flaw was found in gnutls. This vulnerability occurs because gnutls p ...
GHSA-6rgh-57xm-37v8
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
BDU:2026-07116
Уязвимость функции compare_strings() библиотеки GnuTLS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260625-73-0015
Уязвимость gnutls
SUSE-SU-2026:2924-1
Security update for gnutls
SUSE-SU-2026:2923-1
Security update for gnutls
SUSE-SU-2026:2087-1
Security update for gnutls
RLSA-2026:20611
Important: gnutls security update
ELSA-2026-20611
ELSA-2026-20611: gnutls security update (IMPORTANT)
SUSE-SU-2026:2115-1
Security update for gnutls
openSUSE-SU-2026:20778-1
Security update for gnutls
RLSA-2026:20613
Important: gnutls security update
RLSA-2026:20612
Important: gnutls security update
ELSA-2026-50346
ELSA-2026-50346: gnutls security fix update (IMPORTANT)
ELSA-2026-20613
ELSA-2026-20613: gnutls security update (IMPORTANT)
ELSA-2026-20612
ELSA-2026-20612: gnutls security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-3833 A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-3833 A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-3833 A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-3833 Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison | 1% Низкий | 3 месяца назад | ||
CVE-2026-3833 A flaw was found in gnutls. This vulnerability occurs because gnutls p ... | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
GHSA-6rgh-57xm-37v8 A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
BDU:2026-07116 Уязвимость функции compare_strings() библиотеки GnuTLS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.4 | 1% Низкий | 5 месяцев назад | |
ROS-20260625-73-0015 Уязвимость gnutls | CVSS3: 7.4 | 1% Низкий | около 1 месяца назад | |
SUSE-SU-2026:2924-1 Security update for gnutls | 18 дней назад | |||
SUSE-SU-2026:2923-1 Security update for gnutls | 18 дней назад | |||
SUSE-SU-2026:2087-1 Security update for gnutls | 2 месяца назад | |||
RLSA-2026:20611 Important: gnutls security update | 2 месяца назад | |||
ELSA-2026-20611 ELSA-2026-20611: gnutls security update (IMPORTANT) | 2 месяца назад | |||
SUSE-SU-2026:2115-1 Security update for gnutls | 2 месяца назад | |||
openSUSE-SU-2026:20778-1 Security update for gnutls | 2 месяца назад | |||
RLSA-2026:20613 Important: gnutls security update | около 2 месяцев назад | |||
RLSA-2026:20612 Important: gnutls security update | около 2 месяцев назад | |||
ELSA-2026-50346 ELSA-2026-50346: gnutls security fix update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-20613 ELSA-2026-20613: gnutls security update (IMPORTANT) | 15 дней назад | |||
ELSA-2026-20612 ELSA-2026-20612: gnutls security update (IMPORTANT) | около 1 месяца назад |
Уязвимостей на страницу